← Back to Docs
What We Collect
Threadline collects the minimum data needed to provide the comment service. Here is exactly what we store and why.
Data We Collect
| Data | Source | Purpose | Retention |
|---|---|---|---|
| Comment text | User | Display comments | Until deleted or account closed |
| Display name | User | Attribute comments | Until account closed |
| Email (if provided) | User | Authentication, password resets, notifications | Until account closed |
| Password (if set) | User | Account authentication | Bcrypt-hashed; never stored in plaintext |
| IP address | Automatic | Rate limiting (not persisted), admin security audit logging | Not persisted for commenters; up to 1 year in admin audit logs |
| Page URL + title | Automatic | Group comments by page | Until site deleted |
| Reactions (likes) | User | Show reaction counts | Until comment deleted |
Data flow
What moves when a reader comments - and what never enters the pipeline:
What We Do NOT Collect
- We do not set third-party cookies
- We do not track users across sites (no cross-site tracking)
- We do not use your comment data for advertising
- We do not sell data to third parties
- We do not require real names or phone numbers
- We do not store IP addresses of commenters or visitors in our analytics database
Publisher-Specific Data
If you are a site publisher (not a commenter), we also store:
- Your site URL and name
- Moderation settings and word filter rules
- Webhook URLs (encrypted at rest)
- API keys (hashed, not reversible)
- Pageview counts (aggregated, not per-visitor)
See also: GDPR compliance guide · How to export your data · Full privacy policy