Don't take our word for it. Open your browser's developer tools (Network tab) and audit Bare yourself. This page lists every kind of request you should see, what it contains, and why it exists. If you find anything not listed here, we want to know: contact@searchbare.com.
1. App files from this domain. HTML, scripts, styles, and icons that make up the interface. Static files, no data about you.
2. One POST request per search. When you search, a single request goes to Bare's backend containing only your query text and the tab (web or images). No location, no identifiers, no cookies attached by us. The response is marked do-not-store so nothing along the way caches it.
3. Framework boot requests. On load, the app framework fetches the app's public settings (its own configuration, nothing about you), and may also fire a sign-in check (a "me" or "User/me" request). Bare has no accounts, so that check always comes back empty or "authentication required". the error is the proof there's no account to look up. Nothing personal is sent in either request.
4. Anonymous page-view and heartbeat pings. The hosting platform counts page views so we can see the service is used. You'll see two kinds: a page-view log per page you open (page name only), and a periodic batch ping while a tab stays open, carrying a random per-visit session identifier and a timestamp, effectively "a tab is still open", nothing more. Check localStorage: Bare deletes any key containing "analytics" before the app boots, on every load, so that identifier can never persist across visits or stitch one visit to the next. Your search queries and clicked links' destinations are never in these pings, and we have no way to turn them into a profile. These are injected by the hosting platform (Base44), not written by Bare; if the platform changes them, we'll update this page. To be direct about a specific claim we've seen online: Bare's own code does not track which searches you make or which links you click. check ResultItem.jsx and useSearch.js in the source, or simply watch the Network tab as you click a result. Every outbound link uses referrerPolicy="no-referrer" and there is no click handler anywhere that reports the destination back to us.
5. Image thumbnails (image search only). Thumbnails on the images tab come from two kinds of hosts: Brave Search's image proxy (imgs.search.brave.com), which shields you from the original sites, and open media libraries (Wikimedia Commons, Openverse) whose thumbnails load directly from those hosts. In every case the request carries at most this site's bare origin as referrer, never your search query, but a directly-loaded thumbnail does mean that media host sees the image request from your connection. This applies to the images tab only; web results load nothing from any result site.
6. Backend calls from the news, sports, and widgets pages. These pages fetch their data through Bare's own backend, same as search. The request contains only the category, league, or topic being viewed. the news and sports sources are contacted by our server, never by your browser, and responses are served from a short shared cache.
No third-party ad or tracker scripts. the page's security policy forbids loading scripts from any outside origin. No tracking cookies. No fingerprinting calls. No requests to the websites listed in your web results until you click one (the images tab loads thumbnails as described in point 5 above). No referrer carrying your query when you do click (we send origin only, and strip tracking tags like utm from result links first).
Framing guard. Try embedding this site in an iframe on another domain, it hides itself and breaks out. This closes the clickjacking vector entirely.
Storage. Application tab → Storage. You'll find on-device preferences (theme, language, quick-answers toggle) and the PWA's app shell. During a visit you may also see the hosting platform's analytics key, reload the page and watch it get wiped before the app boots, so it never survives to the next visit. No query history is stored, ever.
Service worker. The PWA's worker never intercepts or caches search traffic. only same-origin GET requests for the app shell pass through it. Its source is public at /sw.js.
If the platform Bare runs on changes its injected behavior, this page will be updated to match. Found a discrepancy? Tell us and we'll fix it or document it, no exceptions.