Skip to content
Garrul
  • Features
  • Install
  • FAQ
  • Terms
  • GitHub

Privacy Policy

Last updated: July 31, 2026

The short version

Garrul is open-source software you run on your own servers. This website is a brochure for it, plus a live demo of the comment widget at the bottom of the homepage.

We don't run ads, we don't sell anything to anyone, and we don't hand your data to data brokers. If you comment on the demo, we store your comment and the name you signed in with — because that's how comments work. If you never comment, we keep no account for you at all.

On this page

  1. Who this policy covers
  2. What the website collects
  3. What the demo comment section stores
  4. Google sign-in data
  5. Who else sees any of this
  6. How long we keep things
  7. Your choices and how to use them
  8. If you run Garrul yourself
  9. Children, transfers, and changes
  10. Contact

1. Who this policy covers

There are two separate things wearing the Garrul name, and it's worth keeping them apart:

  • This website and its demo. garrul.com and the demo comment section on the homepage (served from comments.garrul.com) are operated by KingPin, an individual developer based in New York, USA. This policy describes those, and only those.
  • Garrul the software. Anyone can download Garrul and deploy it to their own Cloudflare account. If you're leaving a comment on someone else's blog that happens to run Garrul, that site's operator holds your data — not us. We have no access to their database and no way to look anything up in it. Their privacy policy applies to you, not this one.

Throughout this page, "we" and "us" mean the operator of this website. "Garrul" means the software.

2. What the website collects

You can read every word on this site without signing in, and we don't ask you to. Here's what happens anyway, because it happens on every website:

Hosting logs
The site is served by Cloudflare Pages, which keeps standard request logs — your IP address, browser user-agent, the URL you asked for, and a timestamp. These exist so that attacks and abuse can be traced. We don't build profiles from them.
Cloudflare Web Analytics
Counts page views and referrers in aggregate. It sets no cookies and does no cross-site tracking.
Umami analytics
A privacy-focused, cookie-free analytics tool we host ourselves at tr.kpsn.dev. It records page views, referrers, and rough device/country information. Nothing is shared with a third-party ad network, because there isn't one.
Session recording
Worth being upfront about: roughly one in three visits also records a playback of on-page activity — clicks, scrolling, and cursor movement — for up to five minutes. Text you type is masked before it leaves your browser. We use these to find the spots where the page confuses people, and nothing else. It runs from the same self-hosted tr.kpsn.dev; blocking that host in your content blocker or browser extension stops it, and the site works fine without it.
Web fonts
Typefaces load from fonts.bunny.net, a privacy-oriented font CDN that states it logs no personal data and sets no cookies. Your browser does have to request the files from them.

What the site deliberately does not do: no advertising or ad-retargeting pixels, no social media trackers, no fingerprinting scripts, no selling or renting of data, and no participation in Google's Topics/FLoC ad-interest APIs — those are switched off at the HTTP header level.

3. What the demo comment section stores

The homepage has a working Garrul instance on it so you can try the thing before you install it. Anything you post there is a real comment in a real database, and it's public — treat it like any other public post and don't put private details in one.

If you sign in with an OAuth provider

We store the provider you chose (GitHub, Google, Discord, Facebook, or X), your account ID at that provider, your display name, your avatar image URL, and your email address if the provider tells us it's verified. We never receive or store your password.

If you post anonymously

We store the display name you typed and a hashed version of your IP address. No account is created.

With every comment

  • The text you wrote, as both markdown and rendered HTML.
  • Timestamps for posting, editing, and deletion.
  • Your IP address hashed with HMAC-SHA-256 and a secret key that stays on the server. The raw address is never written to storage. The hash lets us rate-limit and block abuse without keeping a record of where you live.
  • Your browser's user-agent string, used for spam triage.
  • Any reactions or votes you leave, linked to your account.

Notification emails

If — and only if — you opt in to reply notifications, we store your email address against that thread plus an unsubscribe token. Every notification email carries a one-click unsubscribe link. Delivery goes out through Resend.

Sign-in cookie

Signing in sets exactly one cookie, holding a random session identifier and nothing else. It's HttpOnly, Secure, and partitioned, so scripts can't read it and it can't be used to follow you around other sites. The matching session record lives in Cloudflare KV and expires after 30 days. There are no advertising, analytics, or tracking cookies anywhere on this site.

Spam checks run on comment text before it's published — a honeypot field, rate limits, markdown sanitising, and Cloudflare Turnstile, which is a CAPTCHA alternative that doesn't profile you. Suspicious comments go into a moderation queue for a human to look at rather than vanishing silently.

4. Google sign-in data

If you choose Sign in with Google, Garrul requests three standard scopes and nothing more:

  • openid — confirms you are who Google says you are, and gives us a stable account identifier so we can recognise you next time.
  • profile — your display name and profile picture URL, shown next to your comments.
  • email — your email address, stored so we can attach your comments to your account and send reply notifications if you ask for them.

That data is used only to sign you in, label your comments, and moderate the comment section. Specifically, we do not:

  • use it for advertising, ad targeting, or personalisation of any kind;
  • sell, rent, or transfer it to data brokers, information resellers, or anyone else;
  • use it to train machine-learning or AI models;
  • let humans read it, except where you've explicitly asked us to, where it's necessary for security or moderation (for example investigating spam or abuse), or where the law requires it.

Garrul's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including its Limited Use requirements.

You can disconnect Garrul from your Google account at any time at myaccount.google.com/permissions. That stops future sign-ins; to also erase what we already hold, ask us to delete it — see your choices below.

5. Who else sees any of this

Nobody buys this data from us, because we don't sell it. The only outside parties involved are the services needed to run the site:

  • Cloudflare — hosting, CDN, the D1 database, KV storage, and Turnstile.
  • The OAuth provider you picked — it knows you signed in to Garrul, because you signed in through it. Your avatar image is also loaded from that provider's servers when your comment is displayed.
  • Resend — only if you opted into notification emails, and only your email address plus the message.
  • fonts.bunny.net — serves the fonts.

Beyond that, we'd disclose information only if we were legally required to, or if it were genuinely necessary to investigate abuse or protect someone's safety. If that ever happens and we're allowed to tell you, we will.

6. How long we keep things

  • Comments stay until you or a moderator delete them. This is a public archive by design — old threads stay readable.
  • Accounts stay while you're using them, and until you ask us to delete yours.
  • Sessions expire automatically after 30 days, or immediately when you sign out.
  • Rate-limit counters expire on their own within minutes to hours.
  • Email subscriptions are deleted when you unsubscribe.
  • Analytics and hosting logs are kept on the retention schedules of the services above — weeks to months, in aggregate.

7. Your choices and how to use them

Depending on where you live, you may have formal rights under the GDPR, the UK GDPR, or laws such as the CCPA. We'd rather not make you cite a statute: just ask, and we'll do it.

  • See what we hold about you, or get a copy of it.
  • Correct it if something's wrong — you can edit your display name yourself.
  • Delete it. We'll remove your account and, if you want, your comments along with it.
  • Stop the email. Use the unsubscribe link, or tell us.
  • Withdraw sign-in access at your provider, as described above.
  • Complain to your local data-protection authority if we've handled something badly. We'd appreciate the chance to fix it first.

Email [email protected] and we'll get back to you. We aim to respond within 30 days, and we won't charge you or make you jump through hoops.

One heads-up on that address: it's a Google Group, so depending on the group's settings, messages sent to it may be visible to other members or archived. If your request involves details you'd rather not put somewhere semi-public, say so in a short message and we'll move to a private channel before you send anything sensitive.

8. If you run Garrul yourself

The moment you deploy Garrul to your own Cloudflare account, the data belongs to you and this policy stops being the relevant document. Under the GDPR you are the data controller for your commenters; we are not a processor for you, because we never touch your instance.

Practically, that means you should publish your own privacy notice covering what your deployment stores. Garrul is built to make that easy to honour: IPs are hashed by default, there are no third-party trackers in the embed, and the database is plain SQLite you can export or delete from at will. You're welcome to use this page as a starting point for your own.

9. Children, transfers, and changes

Children

This site isn't aimed at children, and the comment demo is for people 13 and over. We don't knowingly collect anything from a child under 13 — if you believe we have, email us and we'll delete it.

Where your data goes

We're in the United States and the site runs on Cloudflare's global network, so your information is processed in the US and potentially at whichever Cloudflare data centre is nearest you. If you're in the UK or the EEA, that means your data may be transferred outside your region; Cloudflare's transfer safeguards, including Standard Contractual Clauses, cover that leg.

Changes to this policy

If we change how any of this works, we'll update this page and move the date at the top. For anything significant we'll note it in the comment section on the homepage rather than quietly editing the text. If you ever want to know what an earlier version of this page said, ask and we'll tell you.

10. Contact

Questions, requests, or corrections: [email protected]. Bugs and feature requests are better off as an issue on GitHub, where everyone can benefit from the answer.

See also: Terms of Service.

GitHub · Sponsor · Ko-fi · Privacy · Terms

Built by KingPin. Garrul is open source. License: Apache 2.0.