Marketing without surveillance funded by NLnet

Image of two hands holding white jigsaw pieces, one saying 'idea' and the other saying 'funding' and they seem to be coming to join together. It has the NLNet and Mautic logos on the bottom with the NGI Zero Core logo on the right. The background is a grey colour.

TL;DR: NLnet just awarded Mautic just over €72,000 through the NGI Zero Commons Fund to build the first marketing automation platform that can run with no tracking or surveillance at all. Starting in September, over the next roughly eight months we’re building three things: a way to run every part of Mautic without setting a cookie, need-to-know access controls so not everyone can see every contact, and a privacy centre where you can see and control every tracking setting in one place. Want a say in how it’s built? Everything goes through an open RFC on our Community Portal first – follow the assembly to receive updates.

Something we’ve been mulling over for quite some time in Mautic’s product development is what would Mautic be like if we took out all of the surveillance? What does marketing automation look like without it?

For most tools on the market, the answer is not very much. Tracking is not a feature bolted onto marketing platforms, it is the ground on which they’re built. Most don’t even allow you to turn off the tracking that they ship with.

Does it really have to be this way?

I’m delighted to share that NLnet has awarded Mautic just over €72,000 through the NGI Zero Commons Fund to enable Mautic to become a product that enables exactly that – being the world’s first marketing automation platform which can run with no surveillance and tracking features at all, and that enables the marketer to selectively turn on each tracking feature on a granular basis with the full knowledge of the privacy impact that results from each decision.

What we’re building

Over the next eight months or so starting in September, we’ll be doing three things.

First, we’re making every part of Mautic capable of working without setting a cookie.

Today, forms set cookies unless you put them in kiosk mode. Asset downloads, redirect links and focus items always set them. The tracking pixel sets them. Forwarded emails set them, and can advance a campaign for someone who never opted into it. There’s no way to revoke a Mautic cookie once consent is withdrawn, and the Gravatar integration reaches out to a third-party server every time you open a contact record, with no way to turn it off.

It might be that after we carry out the research, we find that some cases, a feature or functionality might not be able to work without a cookie being set, in which case we should only set that cookie once we’ve informed the customer what we’re doing and why, and be sure to clean up afterwards where appropriate.

We’ll also give form submissions a retention period, since they currently sit in the database indefinitely because the cleanup job doesn’t touch them. We’ll surface Mautic’s Do Not Track and Global Privacy Control handling in the interface, because the community made Mautic honour those signals back in February and there’s no way to tell from looking.

Each of these might seem small on its own, but together they present a real challenge where privacy is important to the Mautic user and their customers.

Second, we’re building access controls that work on a need to know basis. Right now, if you can see contacts in Mautic, you can see everything about every contact. For an agency that’s an inconvenience. For a government department, a political party or a human rights organisation it’s a reason not to use the software at all. We’ll be adding field-level permissions, controls over who can see engagement data, separation of contacts between teams, and audit logging that records who looked at what and when.

Third, we’re building a privacy centre. One screen where you can see and change every tracking setting, understand what each one actually does before you enable it, and audit your own configuration. Some of these settings currently live in a config file with no user interface at all, so this will be a massive improvement in both educating the marketer and enabling them to make choices when it comes to privacy. Once the groundwork is done, Mautic will eventually ship with tracking turned off, so that enabling it becomes a deliberate, informed choice rather than a default nobody really thought about.

Of course, alongside this we’ll also be making sure this is very well documented, provided through a carefully designed user experience, and with lots of public communications to ensure that the switch from track-all-the-things to track-nothing-and-turn-on-what-you-need is well understood.

Building on what came before

This project hasn’t come out of nowhere. It was first proposed in 2023 by members of the German speaking Mautic community following a sprint, and accepted on our roadmap. Since then, we’ve since been iterating on it and developing it into a formal, scoped project plan.

The UX and UI overhaul we’ve been working on since Mautic 5 including adopting the Carbon Design System, gave us the design foundations to build something as information-dense as a privacy centre without it being overwhelming. Our NLnet-funded Campaign Portability work, which we’ve just completed the second phase of, taught us how to run a funded project inside an open source community, with consultation in public, specifications agreed before code, and delivery on time and within budget.

Since we formally proposed this to NLNet, some of this work has already started without us. The community has landed Do Not Track and Global Privacy Control support, and has begun separating essential scripts from tracking scripts. Where that’s happened, we’ve cut our scope and reallocated the funding to stretch tasks. Two of our milestones also exist specifically to finish some other community pull requests that have been sitting open for months, to get them over the finishing line. That is what funding should do in a project like ours. Not duplicate volunteer effort, but unblock it and accelerate it further forwards.

Why the focus on privacy and no tracking by default?

First and foremost, because it’s just the right thing to do. Plain and simple.

Why? Privacy and rights to anonymity continues to be eroded, largely driven by the marketing industry.

Authorities increasingly use digital surveillance to identify activists, journalists and marginalised communities. Research in the Internet Policy Review has documented how marketing data specifically gets weaponised against vulnerable people through device fingerprinting and behaviour tracking (Strycharz and Duivenvoorde, 2021).

Organisations serving at-risk communities face a real challenge. They need to reach their audiences, and the tools available to do that create the exact vulnerabilities they’re trying to protect people from. So they self-censor, or they use nothing.

We already have a large government employment agency and a European political party running Mautic. They chose Mautic because self-hosting gives them sovereignty over their data. What we owe them, and the organisations doing riskier work who haven’t been able to choose us yet, is software where that sovereignty goes all the way down the marketing stack and enables them to choose exactly what suits their specific needs.

There’s a second audience I care about just as much, and that’s marketers who have never been given a reason to question any of this.

When you install a tool and tracking is already on by default, you don’t decide to track people, you simply never decide not to. Changing the default changes the conversation. It educates marketers to think more carefully about what they are doing, why they are collecting data, and the implications of doing so. It gives them the opportunity to actually decide to not use tracking, if they don’t need to.

Laying the ground for our AI work

The work we’re doing here is also important, and foundational, to our upcoming AI Initiative.

Any AI capability worth having in a marketing platform needs to work with contact data. That means the questions of what data we hold, who inside an organisation can see it, what leaves the instance, and what the person the data describes has agreed to, all become considerably sharper. A platform that cannot currently tell you which of its features set a cookie or control who has access to what fields at a granular level is not a platform ready to answer those questions.

So the granular permissions, the audit logging and the central privacy configuration we’re building here are not a detour from AI work. They’re the prerequisites for doing it in a way that respects the people on the other end of the campaign. We’re building the controls first, on purpose.

How to get involved

Everything happens in the open. The specification and the design work will go through a RFC on our Community Portal before code is written, and I’d really encourage you to get involved with that. We would much rather hear that we’ve got something wrong at the wireframe stage than after it ships as a PR.

If you run Mautic somewhere the stakes are high, whether that’s a public body, a political organisation or a group defending human rights, I’d particularly like to hear from you. The people who understand these requirements best are the people living with them.

My thanks to NLnet and the NGI Zero Commons Fund. Funding the parts of open source software that nobody can afford to volunteer for is quiet, unfashionable work, and it’s the reason projects like ours can take privacy seriously rather than aspirationally.

What would you want to be able to switch off first?


References and useful resources

International Center for Not-for-Profit Law (ICNL) (n.d.) Enhancing Digital Civic Space Through the OGP Process. Washington, DC: ICNL. Available at: https://www.icnl.org/wp-content/uploads/OGP-digital-commitments-final-new-logos.pdf (Accessed: 18 August 2026).

Vesteinsson, K. et al. (eds.) (2025) Freedom on the Net 2025. Washington, DC: Freedom House. Available at: https://freedomonthenet.org (Accessed: 18 August 2026).

Strycharz, J. and Duivenvoorde, B. (2021) ‘The exploitation of vulnerability through personalised marketing communication: are consumers protected?’, Internet Policy Review, 10(4). Available at: https://policyreview.info/articles/analysis/exploitation-vulnerability-through-personalised-marketing-communication-are (Accessed: 18 August 2026).

Share this blog article:
Picture of Sīlavāpi Cheesley

Sīlavāpi Cheesley

Sīlavāpi (ex Ruth) is an Open Source advocate with over 18 years of experience using and contributing to many different projects. Having served on the Community Leadership Team of the Joomla! project and built a full-service digital agency, she now works as Project Lead for Mautic, supporting the community who build and maintain the world’s first Open Source Marketing Automation platform. Sīlavāpi is an ordained Buddhist in the Triratna Buddhist Order. She's a lover of cats, a keen triathlete and flautist (but not at the same time!) and is based in the East of England.

More 📝's in ,

Image of a stage with spotlights shining on it
Community news

Nominations are open for the 2026 Mautic Awards

It’s that time again! A chance to shine among your peers and be recognized in one of the most anticipated celebrations in the Mautic ecosystem.

Search

Use the search bar above by typing terms and pressing enter.