Privacy
fivebar counts visits without knowing who made them. This is what it keeps, what it does not, and for how long.
Site visitors
A site that uses fivebar loads a small script from fiveb.ar on its pages. Its owner chose to, and decides what their pages send; fivebar counts on their behalf, and they see the totals. fivebar sets no cookies and keeps nothing in the visitor’s browser.
For each page seen, the script sends the page’s address, the address of the page before it, the width of the window, and whether the browser says a script drives it. As the page is left, it sends how long it was on screen, how far down it was read, and how quickly it loaded. It also sends clicks on links to other sites, files downloaded, and anything the site’s own pages add, such as a sign-up, a page’s author or what was searched for on the site. Like any request a browser makes, each one carries the visitor’s IP address and user agent. A site can load the script and send what it counts through its own domain, and its server then passes the visitor’s IP address on to fivebar, with where they are if it knows, to be used as below.
What is kept
Counts, by site and by day: so many pageviews of a page, from a country, in a browser. Never a record of what one visitor did. What they are counted by:
- The page’s path, without its query string or anything after
#. - Where the visitor came from: the host of the page before, or a campaign tag in the address, such as
utm_source. - Country, region and city, and the network the visit came through, such as an internet provider, by its number, all worked out from the IP address, or as a site’s own server passes them on.
- Browser, operating system, and whether a phone, tablet or desktop.
- Time on screen, how far down the page was read, and how quickly it loaded.
- The host and path of a link to another site, and the path of a file downloaded.
- What the site’s own pages add, less any value that looks like an email address.
- What was searched for on the site, where its owner counts its searches: in lower case, cut to 100 characters, and never a search that looks like an email address or holds a number of 9 digits or more, such as a phone or card number.
- The page’s HTTP status, such as 404.
- Whether a visit was taken for a bot’s, and why, such as a crawler’s or one from a hosting network, with the name of a bot fivebar knows, from a list of its own, such as Google. A bot’s pageviews are counted apart from people’s, by the hour, by the page, where it came from, its country and network, and its browser and operating system, and nothing else it sends is kept.
The counts are kept until the site is deleted, which deletes them with it. Copies stay in the backups taken before, until those are deleted in turn.
What is not
| What | Used for | Kept |
|---|---|---|
| IP address | Telling visitors apart, where they are, and whether the site excludes them | No |
| User agent | Telling visitors apart; the browser, system and device; whether it’s a bot, and which known bot | No |
| Window width | Phone, tablet or desktop | No |
| Whether a script drives the browser | Whether it’s a bot | No |
Query string and # | Campaign tags, and what was searched for, as above | No |
| The page before | Its host | No |
| Visitor code | Counting a visitor once a day, and a visit’s pages together | 30 hours |
| Daily secret | Making the visitor code | Until midnight |
To tell one visitor from another, fivebar makes a code from a secret, the site, and the visitor’s IP address and user agent, one way, so the code cannot be turned back into either. The secret is replaced at midnight in the site’s time zone, and the old one is never kept, so tomorrow’s code for the same visitor is a different one, and nobody, fivebar included, can tell that a visitor today was here yesterday. The code itself is kept for 30 hours, longer than any day, then deleted, and a visit’s pages are joined by it until 30 minutes after the last. A visit taken for a bot’s gets no code at all.
So fivebar cannot find, show or delete one visitor’s visits: nothing it holds says which were theirs. To ask
about a site’s analytics, ask the site. A content blocker that blocks fiveb.ar stops the script
altogether.
fiveb.ar itself
fiveb.ar is counted by fivebar, exactly as above, signed in or not. In the app, clicks on links are not counted, and a site’s name or a sign-in link in a page’s address is left out.
If you have an account
- Your email address, which is your account. There are no passwords: each sign-in is a link emailed to you, which works once, within 15 minutes. A one-way hash of the link is kept beside the address until the link is used, or cleared out once it has run out. An address with no account, typed into the sign-in form, is kept the same way, and sent nothing. A site’s email reports go to it too, if you turn them on.
- Your sites, the groups they are in, their time zones, goals and search rules, whether their stats are public, which email reports you have turned on and when each was last sent, and the time zone you start new sites in. So is the traffic a site excludes, until it is removed: addresses, which can be your own, networks by number and sometimes name, and countries.
- A cookie,
__Host-fivebar, that keeps you signed in for 30 days, or until you sign out. Only a one-way hash of it is kept. Asking for a link on the way to connecting an app sets a second,__Host-fivebar-app, for 15 minutes. Both are only for signing in, and there are no others. - The apps you connect, such as Claude or ChatGPT: each app’s name, where it sends you back to, whether you let it change settings, and the tokens it reads your stats with, which last an hour and are renewed for up to 30 days. An app that registers itself is kept for 90 days. Settings lists them, and disconnects any of them. What an app reads is then the app’s, under its own terms.
- The API tokens you make, for scripts that read the stats API: each one’s name, if you gave it one, whether it reads all your sites or which ones, when it was made and when it was last used, updated at most once an hour, and a one-way hash of it, never the token. Each lasts until you revoke it in Settings.
- If you go to pay for a plan, the company that takes the payment is given your email address and a reference to your account, and holds what you give it to pay: your name, your card, your billing address and your tax ID if you give one, with your invoices. fivebar never sees your card. fivebar keeps which customer of theirs your account is, and each of your plans as they last said it was: which plan, in which currency, what it costs, whether it is still going, and when it renews or ends. A plan that has ended is kept with your account. The messages they send to say a plan has changed are kept, by their reference and what kind of change each was, for 30 days. What the company holds is theirs, under their own terms and the law on keeping invoices, and stays with them after your account is deleted.
- Feedback an app sends fivebar for you, which fivebar asks the app to send only once you’ve seen it and agreed: the note, in your words, of up to 1,000 characters, what kind of note it is and the tool it is about, the host the app publishes its details at, the version of fivebar’s tools, and when it was sent. Only fivebar reads it. It is deleted with your account, or after a year, whichever comes first.
What your account holds is kept until it is deleted. Deleting a site in its settings deletes its counts at once. To have your account deleted, with its sites, email mail@fiveb.ar.
If you join the beta
The form on the home page keeps your email address, your name, the web address of the site you would use fivebar on, and the day you gave them, so we can tell you when there is room for your site. We send one email to say thanks, and nothing more until then; joining again, or from a +tag of the same address, sends nothing. It is not an account, and it is kept until you come off the list. To come off it, reply to that email, or email mail@fiveb.ar.
Asking for a sign-in link, joining the beta, checking a site with the installation checker, or an app registering itself, is limited per IP address, counted for a minute and not kept. The checker keeps nothing of what it reads. Reading the stats API with a token is limited per account, the same way.
Logs
Requests are not logged. What fivebar’s code writes to its logs when something goes wrong is kept for up to seven days, for finding faults. It never includes a visitor’s IP address or user agent, and can include an account’s email address, where something about it goes wrong or it is deleted.
The calls an app makes to fivebar’s tools are counted: by the day, the tool, the kind of app, by where it publishes its details, and, where the call was refused or its filters matched nothing, what was wrong with it, such as a country given as a name rather than a code. The counts keep no account and nothing a call asked, and are kept for 30 days.
Where it lives
Each request is handled near where it was made, which can be anywhere in the world.
- The counts are kept in a database in Germany, with its backups in Western Europe. What a page reads of them can be held for up to a minute near where it was read.
- Accounts and the beta’s list are kept in Western Europe, and copied around the world so that pages can read them quickly wherever they are asked for.
- A copy of each site’s settings, and the apps you connect, are kept around the world.
- Visitor codes, the visits still going on, counts not yet saved and the daily secrets are kept near where each was first needed, which can be anywhere in the world.
- The logs, and emails as they are sent, can be outside Europe too.
Who else handles it
Nothing is sold, or given to anyone to use for their own ends. The companies that run fivebar’s servers handle it only to run them. If you go to pay for a plan, the company that takes the payment has your email address, a reference to your account, and your name, your card, your billing address and your tax ID if you give one, to take it. fiveb.ar runs no other company’s analytics or advertising.
Why
An account’s details are kept to run the account you asked for, an address, name and site on the beta’s list to tell you when there is room, as you asked, and the logs to keep it working and secure. The counts are kept for the site’s owner, who uses fivebar to see how their site is used, and who is responsible for that choice.
Changes
When what fivebar keeps changes, this page changes with it. It last changed on 6 October 2026.