← Back to Docs

What We Collect

Threadline collects the minimum data needed to provide the comment service. Here is exactly what we store and why.

Data We Collect

DataSourcePurposeRetention
Comment textUserDisplay commentsUntil deleted or account closed
Display nameUserAttribute commentsUntil account closed
Email (if provided)UserAuthentication, password resets, notificationsUntil account closed
Password (if set)UserAccount authenticationBcrypt-hashed; never stored in plaintext
IP addressAutomaticRate limiting (not persisted), admin security audit loggingNot persisted for commenters; up to 1 year in admin audit logs
Page URL + titleAutomaticGroup comments by pageUntil site deleted
Reactions (likes)UserShow reaction countsUntil comment deleted

Data flow

What moves when a reader comments - and what never enters the pipeline:

Reader browserpage + commentEmbedwidget scriptComments APIauth + persistPostgresRedisNOT collectedfingerprints, cross-site trackers

What We Do NOT Collect

Publisher-Specific Data

If you are a site publisher (not a commenter), we also store:

See also: GDPR compliance guide · How to export your data · Full privacy policy