Privacy
Plain-language summary of what flagcounter.me collects when you create or embed a counter. This is not legal advice.
How counters work
A flag counter is a plain image URL. When someone (or a site) loads that image, our servers count a visit. Unique visitors are counted once per IP address for each counter; pageviews increase on every load.
Data we process
- IP address — used to decide whether a visit is unique for that counter, and to look up an approximate country via GeoIP (GeoLite2).
- Country code — stored so the counter image and stats pages can show flags and country totals.
- User-Agent — when present, used to show browser and device breakdowns on the public stats page for that counter.
- Creator IP — stored when a counter is created, for abuse prevention (rate limits and bans). It is never shown in public pages or Client Components.
Cookies
- fc_tz — your browser’s IANA time zone so Today / Yesterday on stats use local calendar days.
- Signed-in session — if you use Sign in (OAuth or magic link), a session cookie keeps you logged in for dashboard and claim flows.
Accounts and passwords
Optional accounts store your email (and provider profile details from OAuth). Counter passwords are stored as hashes so you can customize or claim a counter later. We do not sell personal data.
What stays public
Anyone with a counter’s public code can open its stats page and see aggregates (countries, browsers, devices, relative visit times). Raw IP addresses are not shown on that page. Embed image URLs themselves are public by design — that is how the widget counts.
Ready to embed? Create a free flag counter. More answers in the FAQ.