Changelog
What we added.
Cookieless analytics, website uptime, a public status page, WordPress. Patch deploys are folded. Git still has the steps. Paid used to be one plan. That is Starter and Growth from 1.44.
1.175 · 9 Oct 2026
- A server error is a normal page with a way home. It does not print the error. A missing page counts as cfa('404'), and that error page counts as cfa('500').
1.174 · 8 Oct 2026
- The homepage sample is one pageview line with a soft fill, a grid, and a hover card for the day. Notes on that chart are short ticks.
1.173 · 8 Oct 2026
- The homepage says what it is in the headline: website analytics without a cookie, and the visit still counts after Reject. Price and the week next to Google Analytics sit with the buttons. The plan table on Dutch, German, and French pricing is in that language.
1.170 · 23 Sep 2026
- A Watch down on the traffic chart is a short tick under the column. The column is still pageviews. Hover says whether the outage covered that whole period.
1.169 · 22 Sep 2026
- Chart days follow the site timezone. A pageview after midnight in Amsterdam stays on that day, on the dashboard and on the homepage sample.
- All sites keeps your own numbers when a site you only view is over its volume.
1.168 · 22 Sep 2026
- MCP speaks the July 2026 protocol and the older handshake. An event-stream probe gets 405 instead of a JSON page. Cursor's app callback is allowed. Claude Code can sign in with its client metadata URL. Still read-only. Still no visitor hashes.
1.166 · 14 Sep 2026
- Stripe Connect OAuth comes back to www even without a session cookie after Stripe, and uses the live redirect URI. Read-only still. Not CFA billing.
1.165 · 14 Sep 2026
- The Monday briefing adds Search Console clicks when Google is connected, and one Watch line: downtime or not. Empty Search until you connect. Still no tracking pixel.
1.164 · 14 Sep 2026
- The Monday briefing compares this week to last week: visitors, pageviews, bounce, top pages and sources, plus a table chart. Same dashboard numbers. Still no tracking pixel.
1.163 · 11 Sep 2026
- Watch Fase 4: London as a third sample when Frankfurt failed. Down is still Frankfurt and Dublin. Keyword is its own check. One TCP port on a hostname you already added — not a port scan, not SMS.
1.162 · 11 Sep 2026
- The WordPress zip URL goes to the plugin page. Sitemap lastmod matches the ship date. /unsub without a token stays put. A bad join code is 404. c.cookiefreeanalytics.com serves the tracker, not the homepage.
1.161 · 8 Sep 2026
- Skip-to-content lands on forgot, reset, join, and the OAuth allow page. /unsub is noindex. Watch Slow mail and /docs/watch say first byte, not a network ping.
1.160 · 8 Sep 2026
- Terms put Watch on Starter and Growth, not Hobby. French and Spanish homepage closers drop leftover English. Blog index images keep their alt text. Sample tiles on the homepage (and the dashboard) are valid HTML. Features points tooling at /docs/api and engineers at /methodology.
1.159 · 8 Sep 2026
- Compare counts sixteen tools in the title and the H1. security.txt points at /security. /og.png is HTTP 301 to the JPG.
1.158 · 8 Sep 2026
- Watch Ping on the dashboard is first byte of an HTTPS GET from Frankfurt, not a network ping. The number sits under that sentence.
1.157 · 8 Sep 2026
- The homepage heading stays put when the display font loads. Georgia is sized to Newsreader so the second line does not jump.
1.156 · 8 Sep 2026
- The homepage paints faster on a phone: CSS is in the first HTML, heading fonts start immediately, and the sample chart is SVG so the dashboard chart library is not on that first load.
1.155 · 2 Sep 2026
- Added /security (report to hello@, RFC 9116 security.txt). /og.png 301s to the JPG card. Signed-out /app goes to sign-in. The public sample dashboard no longer ships the country map in the first HTML.
1.154 · 2 Sep 2026
- Added a public status page clients can live on: subscribe to downtime (confirm the address, unsubscribe any time), an owner note on incidents, a status. hostname on Growth (DNS-only CNAME), and a printable monthly uptime report (browser Print / PDF).
- Added a GDPR-friendly analytics page — what we store, Frankfurt beacons, Ireland rows, the public DPA. We still will not stamp “compliant.”
1.153 · 1 Sep 2026
- Public status subscribe (confirm / unsub), an owner sentence on an open incident, Growth status. CNAME (DNS only), and a printable monthly uptime report.
1.152 · 1 Sep 2026
- Added downtime on the traffic chart: when website uptime is down, those hours shade the cookieless analytics graph.
- Added server-error goals with cfa('500'), same visitor spike as 404s. HTTP checks gained status presets and must-not-contain.
1.149 · 1 Sep 2026
- Added a WordPress plugin for cookieless analytics. Paste the public ID; it prints the 1 KB /cf.js snippet. Optional click tracking and 404 goals. First-party stays a c. CNAME — not a PHP proxy.
1.144 · 31 Aug 2026
- Added Stripe revenue on the dashboard. Connect the shop with read-only OAuth (same shape as Search Console). Successful charges for the range; Checkout campaigns only when metadata already has UTM. Not mixed into visitor rows.
1.127 · 31 Aug 2026
- Added Dutch, German, and French for cookieless analytics: home, pricing, WordPress, cookie banner, and Google Analytics alternative pages. Docs, blog, and uptime stay English. Spanish waits.
1.121 · 31 Aug 2026
- Added a public uptime status page: “No problems detected.”, 60-day bars per URL, 7-day incident calendar. Website monitoring is on Features, pricing, and /docs/watch — included on Starter and Growth, not an add-on.
1.115 · 31 Aug 2026
- Added website uptime monitoring (Watch) on Starter and Growth: HTTP, TLS, DNS, sitemap (40 same-host URLs a day), ping charts, and alerts. Frankfurt every check, Dublin if Frankfurt failed. Slow is not down. Hobby sees the tab; checks start when you pay.
1.108 · 30 Aug 2026
- Added TLS certificate days, DNS records, and domain expiry on Watch. First-party cookieless analytics via c.cookiefreeanalytics.com (CNAME, DNS only) is live.
1.103 · 28 Aug 2026
- Watch on the dashboard: Up/Down, ping in ms, green dots, Day/Week/Month/Year. One click watches the hostname you already added. Paid accounts auto-watch sites that already send hits.
1.102 · 28 Aug 2026
- Watch on the dashboard, not the homepage. Status lives at /status. 90-day uptime uses hourly rollups after raw checks age out. A beat closes a missed-heartbeat incident. DNS change mails the owner.
1.101 · 28 Aug 2026
- Dashboard: funnels and goals sit after traffic. Search next. Lighthouse and Landing bounce are two cards. Frankfurt GET details sit in How we measured.
1.100 · 28 Aug 2026
- Lighthouse: the board waits a beat, then asks Google. Refresh Lighthouse always runs a new audit. Scores are not cached.
1.99 · 28 Aug 2026
- Watch: HTTP, TLS, and DNS on a hostname you already added. Frankfurt and Dublin. Mail if both fail. Status page, heartbeat on Starter+, Read API / MCP on Starter+. Included in the plan — no Watch SKU.
1.98 · 28 Aug 2026
- Lighthouse: Performance, Accessibility, Best Practices, and SEO, 0–100, via PageSpeed Insights. Lab, not field. First byte stays the Frankfurt GET.
1.97 · 28 Aug 2026
- First byte: four signals from a Frankfurt GET, then what to do. Not Lighthouse — we do not invent LCP.
1.96 · 28 Aug 2026
- Home meta description fits in a typical Google result.
1.95 · 28 Aug 2026
- In Google: Home, Pricing and the rest of the board are chips. The snippet is clipped to what Google typically shows; title and description length sit under the result.
1.94 · 28 Aug 2026
- In Google: pick a path and see the title and description as a search result. Switch from home to /pricing without leaving the board.
1.93 · 28 Aug 2026
- Chart notes share a row when the pills fit. They only step up when they would collide.
1.92 · 28 Aug 2026
- Chart notes sit above the series, not in the area. A campaign slug is the label; the full Campaign: line stays in the list.
1.91 · 28 Aug 2026
- Set up this site: do not add a funnel that is already on the board. Several distinct paths from your pages can be saved in one confirm. Speed pages only if they are new.
1.90 · 28 Aug 2026
- The over-time chart keeps the tiles you had on, Compare, and Auto / Line / Bars after a refresh.
1.89 · 28 Aug 2026
- Growth funnels: a list you open, conversion rate and dropped on each step, remaining visitors as a line underneath. A path step still filters the board.
1.88 · 28 Aug 2026
- Growth funnels: equal columns left to right, conversion rate and dropped per step, a line of remaining visitors underneath. A path step still filters the board.
1.87 · 28 Aug 2026
- Growth funnels read left to right: each step is a chevron as tall as its share of step 1. The steepest drop is named. A path step filters the board.
1.86 · 28 Aug 2026
- Growth funnels taper with the visitors on each step — the band is as wide as the share of step 1. The steepest drop is named. A path step filters the rest of the board.
1.85 · 28 Aug 2026
- Search Console shows the Google numbers marketers use: clicks, impressions, CTR, and average position — site totals, top queries, and top Google pages, for the same range as the board. Click a Google page to filter the rest of the dashboard. Numbers still trail by a couple of days; we do not invent them.
1.84 · 28 Aug 2026
- Period briefing is a marketer note: an executive summary you can copy for leadership, then demand (sources, campaigns, channels) and the site (pages, entry bounce, goals). Same body type as the rest of the board — not a giant italic lede.
1.83 · 28 Aug 2026
- Dashboard rank lists share one Harbour-ink set: browsers, devices, operating systems, and named referrers (Google, Bing, DuckDuckGo, X, Facebook, LinkedIn, Reddit, Hacker News, Baidu). Unknown hosts stay text-only. No icon CDN.
1.82 · 28 Aug 2026
- Dashboard operating-system marks are the real Apple, Windows, Android, and Linux logos — same ink as the rest of the board, no icon CDN.
1.81 · 28 Aug 2026
- Dashboard campaigns are one panel: Campaigns, Channels (source / medium), Ads, Keywords. Referrers stay the referrer list. Click a row to filter the board. No landing URLs.
1.80 · 27 Aug 2026
- Signup: Continue with Google stays clickable. Miss Terms, Privacy, and the DPA and the box shakes. No 18+ checkbox — the DPA is the extra for visitor pageviews.
1.79 · 26 Aug 2026
- MCP tools declare read-only annotations (title, readOnlyHint) for Claude and ChatGPT directory review. Official Registry listing was already active.
1.78 · 26 Aug 2026
- WordPress plugin zip is a proper plugin folder: paste the public ID in Settings if it was not baked in, WordPress.org readme, uninstall, subdirectory installs.
1.77 · 26 Aug 2026
- Homepage sample: Compare is off until you turn it on. The chart shows dates on X and visitor counts on Y.
1.76 · 26 Aug 2026
- Homepage leads with the consent gap: decline the banner and cookie reports go dark — campaigns look like a miss, ROAS is a sample. We still do not print ROAS or replace ads tags.
1.75 · 26 Aug 2026
- The homepage sample is the live chart, not a picture — click tiles, hover days, compare. A button under it opens the full demo.
1.74 · 26 Aug 2026
- The homepage sample is 30 days. Campaign: launch and Hacker News sit a month apart on the curve, as they do in the seed.
1.73 · 26 Aug 2026
- The homepage sample carries the notes on the curve — Go live, a campaign, Hacker News — same stamps as the live demo.
1.72 · 26 Aug 2026
- The homepage sample is the same six tiles, combo chart, and dashed previous window as the live demo — still a light SVG, not the dashboard bundle.
1.71 · 26 Aug 2026
- Compare overlays the previous window as a dashed line on the chart. Tiles already showed the change. The demo opens with it on.
1.70 · 26 Aug 2026
- Claude and Cursor sign in with OAuth 2.1 on this host instead of pasting a token. Two or more sites open on an all-sites board — each tile is that domain, not a combined graph. The hosted MCP is in the Official Registry so PulseMCP can pick it up.
1.69 · 26 Aug 2026
- Schema, footer, and the GDPR page use Frankfurt + Ireland. The live API blurb no longer says hash.
1.68 · 26 Aug 2026
- Pricing waits two seconds, then points at yearly: pay nine months, keep twelve. It does not flip the toggle for you.
1.67 · 26 Aug 2026
- The public demo chart opens with bounce rate and visit duration on the diagram, and labelled notes on the days they belong to — Go live, a campaign, Hacker News.
1.66 · 26 Aug 2026
- The 60/min ingest cap hashes the IP in the function, not only in Postgres, and a database blip no longer 204s every beacon. Shopify’s app proxy only counts Shopify-signed requests.
1.65 · 26 Aug 2026
- Privacy names xAI (owner-click Grok) and Ireland Postgres. Vs meta that quotes a price now carries the 18 August 2026 list date. Pirsch’s row is Read API + MCP, not “collect + dashboard”.
1.64 · 26 Aug 2026
- Home, pricing, and vs pages spell the /europe split: Frankfurt functions, Ireland Postgres. Titles come from one list. The script POSTs; it does not send a timestamp or fall back to GET.
1.63 · 26 Aug 2026
- Growth funnels are a horizontal strip: visitors, drop from the last step, and share of step 1 on each cell. Several funnels stack. Remove asks Keep or Remove — pageviews stay.
1.62 · 26 Aug 2026
- Period briefing is three short notes (the pattern, the mix, what to open next), not a dump of the tiles. A saved one opens with the dashboard. Writing shows a clock so it does not look stuck.
1.61 · 26 Aug 2026
- The 404 is a full page: the path you asked for, a zero-visitor card, and links to pages that exist.
1.60 · 26 Aug 2026
- The product origin no longer loads grok.com chrome. Login, signup, and /app stay on this host.
1.59 · 26 Aug 2026
- Sign in and Start free in the header paint with the page. Unknown URLs get a 404 with a way out. Login and reset keep their own titles and stay out of the index. /cf.js is cached for five minutes, like the hosted snippet.
1.58 · 26 Aug 2026
- Chart notes stay owner text or first-seen UTM. Unused leftover tables are gone.
1.57 · 26 Aug 2026
- Chart notes are yours, or the first day a UTM campaign shows up. Day-over-day traffic % stamps are gone — the tiles already show volume.
1.56 · 26 Aug 2026
- Grok on the dashboard is capped per account so the shared key cannot be burned: 6 reads a day on Hobby, 12 on Starter, 20 on Growth, four an hour. Cached briefings are free. Set up this site still picks from your pages when the cap is hit.
1.55 · 26 Aug 2026
- Dashboard chart: Auto, Line, or Bars. Auto uses columns for hours and short ranges, a line for longer trends, and volume-as-bars plus rates-as-lines when bounce or duration is overlaid.
1.54 · 26 Aug 2026
- Set up this site: suggest a same-day checkout funnel, landing-speed pages, and goals from events that already fire. Confirmed by the owner. Pages from traffic and the homepage menu — nothing invented. Grok names the plan when XAI_API_KEY is on.
1.53 · 26 Aug 2026
- Period briefing talks to xAI (Grok 4.6) when XAI_API_KEY is set. Refresh writes a new paragraph. Dashboard numbers only — no hashes. Admin shows the gate.
1.52 · 26 Aug 2026
- Account has its own MCP card next to the Read API — numbered steps, Cursor/Claude JSON, Claude Code command, same token. Blog tutorial: ask Claude about pageviews without handing the agent a visitor hash.
1.51 · 26 Aug 2026
- MCP at /mcp: same hashed bearer as the read API. JSON-RPC tools for sites, overview, pages, sources, live, Growth funnels. No visitor hashes. Paste the token in the client header.
1.50 · 26 Aug 2026
- Blog tutorial: the read API as JSON — mint a token, call /sites, then overview, pages, sources, live, Growth funnels. No visitor hashes.
1.49 · 26 Aug 2026
- Read API on Starter and Growth: hashed bearer, the dashboard as JSON (sites, overview, pages, sources, live; Growth funnels). Mint and revoke on Account. No visitor hashes.
1.48 · 26 Aug 2026
- Continue with Google on login and signup when GOOGLE_CLIENT_ID and SECRET are set. Our Cloud client, not the Grok broker. Email and password stay. Google never sees pageviews.
1.47 · 26 Aug 2026
- Live visitors: last page in the last five minutes, grouped by path, high on the dashboard. The pill jumps there. No heartbeat — a tab left open is not a visitor.
1.46 · 25 Aug 2026
- Growth funnels: linear steps (path or cfa event), same UTC day, drop-off on the dashboard. No extra script. Hobby and Starter keep a single goal.
1.45 · 25 Aug 2026
- Blog tutorials: first-party /cf.js, count a signup (events not billed), dual-run next to GA4, share a dashboard, where the rows live. Notes from the first weeks stay below.
1.44 · 25 Aug 2026
- Hobby, Starter, and Growth. Hobby is 3 sites, 90 days, owner plus one viewer, a badge. Starter from €4 (5 sites, 3 viewers). Growth from €8 (10 sites, 10 viewers).
- Volume is a hard wall on the dashboard. Hits stay. Events are not billed. Existing paid accounts stay Growth at their current Stripe amount.
- 1% of each paid charge goes to Stripe Climate. Not a neutrality badge. Hobby has no invoice, so no 1%.
- Owner admin: every account, every site, plan filters, pageviews. Only the house inbox. New-account mail after they confirm the address.
- A busy site is not dropped. 60 beacons/min is still the hashed-IP flood cap.
1.43 · 24 Aug 2026
- Live Stripe: invoices with VAT, yearly (nine months billed, three free). Plan shows this month against last month. Over the billed volume: one mail, a notice, set the next invoice — no dropped pageviews.
- First-party is Path or Subdomain, not both. Apex serves /cf.js without a 301 that blockers follow.
- Team invite mail. Signup confirms the email. Thank-you paths for signup and paid so those can be goals.
- Turnstile on email login when both Cloudflare keys are set. Optional 2FA in account settings — off until you turn it on.
1.41 · 23 Aug 2026
- Operator on DPA, terms, privacy, and footer: Prestons Creek Capital, KvK 42139404, VAT NL005528479B09. Public DPA for visitor pageviews. Street address off the site.
1.38 · 23 Aug 2026
- Dashboard tiles: unique visitors, visits, pageviews, views per visit, bounce, duration. Click to overlay. Duration is last minus first pageview in a 30-minute visit; one-page visits are 0 seconds.
- Locations: countries, regions, cities from the edge headers. No IP, no coordinates.
- Custom date range. Filter bar: is / is not / contains. Landing-page speed on the dashboard (HTML time and bounce on the first page). Not LCP in the tracker.
1.36 · 23 Aug 2026
- Campaign tags in the script and on the server: source, medium, campaign, content, term. The rest is dropped. Still under 1 KB gzip.
1.35 · 23 Aug 2026
- Tagline: No cookies, just insights. Made and hosted in the EU.
1.31 · 23 Aug 2026
- The product name is Cookie Free Analytics on the site, mail, and cards. Domain and cf.js stay.
1.29 · 23 Aug 2026
- Ingest quota in Postgres every isolate shares. Over a hashed IP: 204, no row. Raw IP is not stored.
1.26 · 23 Aug 2026
- Account: download your data, then delete. Sites and pageviews go with it.
- Mail: welcome, site added, first pageview, password changed, payment failed. Paper card, no tracking pixel.
1.23 · 23 Aug 2026
- Functions in Frankfurt. Pageviews in Ireland Postgres. Both EU.
1.19 · 23 Aug 2026
- Harbour UI on the dashboard. Filter bar, notes on the chart.
1.12 · 19 Aug 2026
- First-party CNAME (`c.`) and team viewers. Public share and embed.
1.11 · 19 Aug 2026
- Opt-in clicks as a second file. Default script stays under 1 KB. Chart traffic-% notes shipped here; gone in 1.58.
1.8 · 19 Aug 2026
- Beacon is POST JSON. SPA counts. Query strings allowlisted. HMAC visitors with a pepper and a daily salt we delete.
1.5 · 18 Aug 2026
- Compare and topic pages. WordPress plugin, Shopify snippet, first-party path wizard.
Before this rewrite
Cookie Free Analytics started as CookieFreeAnalytics (Next.js, 17–22 Aug 2026): 1 KB script, HMAC same-day visitors, Harbour design. That git history still exists; the product continues here.