Privacy notice

Minimal data, plainly explained

Grumble Court is designed to discuss public questions without building advertising profiles of visitors.

Submissions

We store the question, explanation, category, moderation state and submission time. Email is optional and used only for consented editorial-state updates. Do not include personal information in case text.

Voting and jury notes

We set a random, first-party, HTTP-only device token. A one-way hash derived from it and the case prevents an obvious duplicate. An optional first instinct is stored on your device; when supplied with a final vote, we store only the two sides and whether they differ. A jury note remains private unless you explicitly submit it for review. Public-gallery text cannot appear until a human approves it, and moderation actions are audited.

Email summons

Case, category and weekly subscriptions require email confirmation. We store the address, requested scope, consent and delivery state. Confirmation and unsubscribe tokens are stored only as salted hashes. Every message has one-click unsubscribe; a suppression record prevents accidental re-sending. Pending unconfirmed requests are deleted after 30 days, delivery logs after 90 days and active subscription records until unsubscribe or deletion request.

First-party product measurement

To understand whether the court is useful, we set a separate random, first-party, HTTP-only journey token for up to 30 days and store only a secret-salted one-way hash of it. We record a fixed list of interactions such as viewing a case, voting, changing an initial view, opening the full brief, sharing, following a referral, hearing another case, requesting a subscription or submitting a problem. It never includes your raw network address, browser user agent, email, submission text or jury-note text, and it is not used for advertising or cross-site tracking. Do Not Track disables this measurement. Marked health and synthetic journeys are excluded from reports.

Privacy-limited Google Analytics

We use Google Analytics only to create aggregate statistics about how Grumble Court is used and to improve the service. The UK Information Commissioner’s statistical-purposes guidance permits this limited service-improvement measurement without prior opt-in when it is clearly explained and accompanied by a simple way to object. For visitors in the United Kingdom, Google Analytics uses host-only first-party session cookies that expire when the browser session ends. For visitors elsewhere, analytics storage is denied and Google receives only cookieless consent-mode measurements. Advertising storage, Google signals and ad personalisation are disabled everywhere.

Google receives the page path without its query string, the page title, fixed interaction names and controlled case or campaign labels. Your browser also supplies ordinary technical information needed to make the request, such as device, browser and network information. We never send your email address, written submission or jury-note text. Do Not Track prevents Google Analytics from loading. The one-click “Turn analytics off” control on every page stores your preference in this browser, removes Google Analytics cookies and stops further Google Analytics requests from Grumble Court.

Abuse prevention

For filing, voting, reactions, reports, jury notes, subscriptions and administrator login limits, a salted hash of basic network information is stored with counters and expiry times in PostgreSQL; the raw address is not stored in that rate-limit record.

Service providers

Cloudflare processes public traffic, Coolify manages deployment and the private PostgreSQL service that stores application records, and the configured email provider delivers confirmed notifications. Google processes privacy-limited aggregate measurement on our behalf with additional account-level data sharing disabled. When an editor requests AI preparation, the approved question and evidence summaries are sent to OpenAI with storage disabled in the Responses API. Following evidence links takes you to the named publisher.

Retention, contact and rights

Anonymous first-party journey events are eligible for deletion after 90 days; expired limits after 7 days; rejected private contributions after 180 days; and editorial/audit records while needed to explain publication and safety decisions. Google Analytics event-level retention is set to the shortest available period. To request access, correction or deletion, email [email protected]. We may ask for limited proof needed to locate an email record; anonymous votes generally cannot be linked back to a person.