Privacy notice

Minimal data, plainly explained

Grumble Court is designed to discuss public questions without building advertising profiles of visitors.

Submissions

We store the question, explanation, category, moderation state and submission time. Email is optional and used only for editorial follow-up. Do not include personal information in case text.

Voting and abuse prevention

We set a random, first-party, HTTP-only device token. A one-way hash derived from it and the case identifier prevents an obvious duplicate. We do not need your name or email to vote. For filing, voting and administrator login limits, a salted hash of basic network information is stored with counters and expiry times in Neon; the raw address is not stored in that rate-limit record.

Service providers

Cloudflare processes public web traffic, Coolify manages deployment, and Neon stores application records. When an editor requests AI preparation, the approved question and evidence summaries are sent to OpenAI; the request is configured not to be stored by the Responses API. Following an evidence link takes you to the named publisher, whose own privacy terms then apply.

Administration

The court office uses an expiring, signed, HTTP-only session and remains disabled until credentials are deliberately configured. Editorial decisions and independent agent runs are logged for accountability.

Retention and rights

Submissions and moderation records are retained while they are needed for editorial review and operation of this MVP. Expired rate-limit records are eligible for routine deletion. A formal deletion schedule, privacy contact and request process must be published before the service is promoted beyond an early public trial.