fivebar

Privacy

fivebar counts visits without knowing who made them. This is what it keeps, what it does not, and for how long.

Site visitors

A site that uses fivebar loads a small script from fiveb.ar on its pages. Its owner chose to, and decides what their pages send; fivebar counts on their behalf, and they see the totals. fivebar sets no cookies and keeps nothing in the visitor’s browser.

For each page seen, the script sends the page’s address, the address of the page before it, the width of the window, and whether the browser says a script drives it. As the page is left, it sends how long it was on screen, how far down it was read, and how quickly it loaded. It also sends clicks on links to other sites, files downloaded, and anything the site’s own pages add, such as a sign-up, a page’s author or what was searched for on the site. Like any request a browser makes, each one carries the visitor’s IP address and user agent. A site can load the script and send what it counts through its own domain, and its server then passes the visitor’s IP address on to fivebar, with where they are if it knows, to be used as below.

What is kept

Counts, by site and by day: so many pageviews of a page, from a country, in a browser. Never a record of what one visitor did. What they are counted by:

The counts are kept until the site is deleted, which deletes them with it. Copies stay in the backups taken before, until those are deleted in turn.

What is not

WhatUsed forKept
IP addressTelling visitors apart, where they are, and whether the site excludes themNo
User agentTelling visitors apart; the browser, system and device; whether it’s a bot, and which known botNo
Window widthPhone, tablet or desktopNo
Whether a script drives the browserWhether it’s a botNo
Query string and #Campaign tags, and what was searched for, as aboveNo
The page beforeIts hostNo
Visitor codeCounting a visitor once a day, and a visit’s pages together30 hours
Daily secretMaking the visitor codeUntil midnight

To tell one visitor from another, fivebar makes a code from a secret, the site, and the visitor’s IP address and user agent, one way, so the code cannot be turned back into either. The secret is replaced at midnight in the site’s time zone, and the old one is never kept, so tomorrow’s code for the same visitor is a different one, and nobody, fivebar included, can tell that a visitor today was here yesterday. The code itself is kept for 30 hours, longer than any day, then deleted, and a visit’s pages are joined by it until 30 minutes after the last. A visit taken for a bot’s gets no code at all.

So fivebar cannot find, show or delete one visitor’s visits: nothing it holds says which were theirs. To ask about a site’s analytics, ask the site. A content blocker that blocks fiveb.ar stops the script altogether.

fiveb.ar itself

fiveb.ar is counted by fivebar, exactly as above, signed in or not. In the app, clicks on links are not counted, and a site’s name or a sign-in link in a page’s address is left out.

If you have an account

What your account holds is kept until it is deleted. Deleting a site in its settings deletes its counts at once. To have your account deleted, with its sites, email mail@fiveb.ar.

If you join the beta

The form on the home page keeps your email address, your name, the web address of the site you would use fivebar on, and the day you gave them, so we can tell you when there is room for your site. We send one email to say thanks, and nothing more until then; joining again, or from a +tag of the same address, sends nothing. It is not an account, and it is kept until you come off the list. To come off it, reply to that email, or email mail@fiveb.ar.

Asking for a sign-in link, joining the beta, checking a site with the installation checker, or an app registering itself, is limited per IP address, counted for a minute and not kept. The checker keeps nothing of what it reads. Reading the stats API with a token is limited per account, the same way.

Logs

Requests are not logged. What fivebar’s code writes to its logs when something goes wrong is kept for up to seven days, for finding faults. It never includes a visitor’s IP address or user agent, and can include an account’s email address, where something about it goes wrong or it is deleted.

The calls an app makes to fivebar’s tools are counted: by the day, the tool, the kind of app, by where it publishes its details, and, where the call was refused or its filters matched nothing, what was wrong with it, such as a country given as a name rather than a code. The counts keep no account and nothing a call asked, and are kept for 30 days.

Where it lives

Each request is handled near where it was made, which can be anywhere in the world.

Who else handles it

Nothing is sold, or given to anyone to use for their own ends. The companies that run fivebar’s servers handle it only to run them. If you go to pay for a plan, the company that takes the payment has your email address, a reference to your account, and your name, your card, your billing address and your tax ID if you give one, to take it. fiveb.ar runs no other company’s analytics or advertising.

Why

An account’s details are kept to run the account you asked for, an address, name and site on the beta’s list to tell you when there is room, as you asked, and the logs to keep it working and secure. The counts are kept for the site’s owner, who uses fivebar to see how their site is used, and who is responsible for that choice.

Changes

When what fivebar keeps changes, this page changes with it. It last changed on 6 October 2026.