·5 min read
What Vector 5 cannot know — and why that is the feature
Who someone is. Whether they came back after midnight UTC. A city, unless you turn it on. Anything about people who block the request. The dashboard prints this next to the numbers.
PrivacyLimits

Every analytics UI is a temptation to over-read. A spike looks like a person. A country looks like an address. Vector 5 puts the refusal in the same chrome as the KPIs: a cannot-know list, repeated in the manifest, the privacy page, and the demo.
- Who a visitor is — there is no account, email, or recoverable hash.
- Whether they returned after 00:00 UTC — the salt is gone.
- Cross-site or cross-device identity — the hash includes site_id and dies daily.
- Exact address — city is optional and off by default; IP is dropped after lookup.
- Anyone who blocked the request entirely — we do not invent them.
If a future feature would let us answer one of those questions, it does not ship. That is a sharper constraint than a brand colour.
The most honest chart is the one with a list of questions it will never answer.

