Privacy notice
Minimal data, plainly explained
Grumble Court is designed to discuss public questions without building advertising profiles of visitors.
Submissions
We store the question, explanation, category, moderation state and submission time. Email is optional and used only for editorial follow-up. Do not include personal information in case text.
Voting and jury notes
We set a random, first-party, HTTP-only device token. A one-way hash derived from it and the case identifier prevents an obvious duplicate. We do not need your name or email to vote. After voting, you may leave an optional jury note explaining your choice. Jury notes are stored privately and are not published without a future editor-reviewed moderation process; do not name or identify anyone.
Anonymous product measurement
To understand whether the court is useful, we set a separate random, first-party, HTTP-only journey token for up to 30 days and store only a secret-salted one-way hash of it. We record a fixed list of interactions such as viewing a case, voting, opening the opposing argument, sharing, following a referral, hearing another case or starting and completing a submission. A record may include the case, referring case, ruling side and short campaign labels. It never includes your raw network address, browser user agent, email, submission text or jury-note text, and it is not used for advertising or cross-site tracking. A browser Do Not Track signal disables this measurement. Marked health and synthetic test journeys are excluded from product reports.
Abuse prevention
For filing, voting, jury notes and administrator login limits, a salted hash of basic network information is stored with counters and expiry times in Neon; the raw address is not stored in that rate-limit record.
Service providers
Cloudflare processes public web traffic, Coolify manages deployment, and Neon stores application records. When an editor requests AI preparation, the approved question and evidence summaries are sent to OpenAI; the request is configured not to be stored by the Responses API. Following an evidence link takes you to the named publisher, whose own privacy terms then apply.
Administration
The court office uses an expiring, signed, HTTP-only session and remains disabled until credentials are deliberately configured. Editorial decisions, anonymous product reports and independent agent runs are available only to the operator.
Retention and rights
Anonymous journey events are automatically eligible for deletion after 90 days. Submissions, optional jury notes and moderation records are retained while they are needed for editorial review and operation of this MVP. Expired rate-limit records are eligible for routine deletion. A formal deletion schedule, privacy contact and request process must be published before the service is promoted beyond an early public trial.