Privacy
What we collect, what we do not, and where it lives. Last updated 22 August 2026.
The short version
Three things touch this project, and only one of them involves your personal data at all:
- The container checker reads files that are already public. No login, nothing personal.
- The CLI keeps your Google and GitHub credentials on your own machine. We never receive them.
- The waitlist is the only place we hold anything about you — an email address you typed in.
The waitlist
If you join, we store the email address you enter and, if you write one, your free-text note. Nothing else.
We use double opt-in: submitting the form does not add you to anything. We send one confirmation email with a link valid for 15 minutes, and your entry activates only when you click it. Unconfirmed entries are deleted. You can request at most three confirmation emails per address in 24 hours.
Our lawful basis under the GDPR is your consent, given by clicking that link. Withdraw it any time at [email protected]. Our emails come from an unmonitored address, so please write to that one rather than replying.
Entries are stored on Cloudflare infrastructure in the European region, kept until we launch and contact you and no longer than 24 months, then deleted.
The container checker
Checking a site fetches its published gtm.js — the same file the site already serves to every visitor — and reads it. There is no login and we do not process personal data to do it.
We do keep a record of what we read: the container id, the site it was found on, and the measurements taken from it. Those records are published on this site, because a container is public business configuration and the point of the dataset is that anyone can check our figures. If you would rather a record you submitted was not listed, use the hide option when you run a check, or email us.
The CLI
When you connect Google or GitHub, the tokens are written to ~/.tagora on your own computer and used from there. They are never sent to us and we have no way to read them. There is no Tagora server in the path between your machine, Google and GitHub.
Google access is requested read-only, so the tool cannot change your container. GitHub access is limited to repositories you select when you install the app.
tagora auth logout deletes the local tokens and revokes the Google grant. GitHub grants are revoked by you at github.com/settings/applications, because doing it for you would require a credential a public tool should not hold.
This website
No advertising, no third-party analytics, no tracking scripts — which would be a strange thing for us to run. The waitlist form uses Cloudflare Turnstile to keep bots out, and Cloudflare may set a token for that purpose and process request data as our hosting provider.
Your rights
You can ask to see, correct or delete anything we hold about you, and to stop being contacted. Email [email protected] and we will act on it.