Cloudflare and Turnstile

Why this library runs on Cloudflare, what Cloudflare sees, and how we plan to keep bots out without puzzles.

Cloudflare hosts this site, runs its community, and stands between it and the internet's floods. Turnstile, Cloudflare's bot check, isn't switched on here yet. This page says what it will do when it is.

What runs on Cloudflare

  • The pages. Cloudflare Pages serves every article from its network.
  • The community. Posts, comments, chat, votes and reports go through a small program on Cloudflare (a Pages Function) into a Cloudflare database (D1).
  • The front door. Every request passes through Cloudflare first. Cloudflare detects and absorbs denial-of-service floods automatically, on every plan, before they reach the site.

What Cloudflare sees

Like any web host, Cloudflare sees your IP address, your browser, and the pages you ask for. Our database on Cloudflare holds:

  • the ID Omxus gives this site for you, different from the one any other site gets,
  • the name you pick,
  • what you post, comment, vote, report and say in chat, and, once uploads are on, your pictures (in Cloudflare R2 storage),
  • a sign-in token, so you stay signed in.

No email address, phone number or password. The site loads no ad trackers and no analytics scripts. Two other services see a page load: Google Fonts, which sends the typefaces and sees your IP address, and Omxus, when you sign in.

Turnstile: bot checks without puzzles

Status: not on yet. Today, sign-in and the limits on posting do the work. See the limits.

Once on, Turnstile will check that a person, not a script, is posting, commenting or reporting. We chose it for three reasons:

  • No puzzles. Turnstile runs small challenges inside your browser, such as a quick calculation and checks for how a real browser behaves, and usually decides without asking you anything. No clicking on traffic lights.
  • Not for tracking. Cloudflare says the signals Turnstile collects are there "solely to detect and block bots", not to identify, profile or target anyone.
  • It doesn't read what you write. Turnstile processes your IP address, your browser's make and connection fingerprint, and which site is asking. Cloudflare says it "does not access, store, or transmit user communications, form entries, or other page inputs".

It also meets the WCAG 2.2 AA accessibility standard, so screen-reader users get through too.

Pictures: almost ready, with two protections

Picture uploads on posts and comments are built, and switch on once their storage is set up. Until then, the site says "Picture uploads aren't switched on yet."

  1. Your browser strips the hidden data first. Photos carry EXIF data: often the GPS spot where you took it, the time, and your phone's model. Before a picture leaves your device, your browser redraws it, which drops all of that. We never receive it.
  2. Cloudflare's CSAM Scanning Tool, coming with it. It compares the pictures we serve against known child sexual abuse material, from lists supplied by child-safety groups such as the US National Center for Missing and Exploited Children. A match is blocked and we're told, so we can remove it and report it.

We also check each file is really a JPEG, PNG or WebP picture under 5 MB, give it a random name, and allow 10 an hour per person. Pictures load only through this site, so when a post or comment is hidden, its picture stops loading too.

Sources. Cloudflare: Turnstile overview, Turnstile privacy addendum, DDoS protection and CSAM Scanning Tool, all read 27 September 2026. What we store and run: this site's code and database schema, read the same day. Turnstile is not in it yet; picture uploads are, waiting on their storage.