churro

Privacy

Churro collects as little as it can. The client never uploads your code, and this website sets no cookies and runs no analytics.

Last updated 29 September 2026.

The Churro client

Churro only ever downloads. It has no way to upload your source code, your build outputs or your project files. To look a dependency up, it asks the cache for a result by an opaque key: a hash worked out from the crate and your build inputs. The request carries the client's name and version (churro/x.y.z) in its User-Agent, and nothing else about you or your project. Your own crates are never looked up: they always compile locally. Like any HTTPS request, these lookups reach the cache at cache.churro.sh, which runs on Cloudflare and sees your IP address and the request itself.

This website

churro.sh is a static site served by Cloudflare. It sets no cookies, runs no analytics or advertising scripts, and has no accounts or forms. Cloudflare processes each request to deliver the site and keep it secure, and keeps its usual server logs, which include your IP address and browser details. See Cloudflare's privacy policy.

The pages load the Google Sans typeface from Google Fonts, so your browser makes a request to Google's font servers when a page opens. See Google's privacy policy.

The public API

The cache also has a read-only JSON API at cache.churro.sh, described in the catalog. It needs no key and no account, and it stores nothing about who asks beyond the ordinary request logs Cloudflare keeps.

Email

If you write to hello@churro.sh, we keep your message and our reply only as long as needed to answer you and follow up. We don't sell or share it.

Your choices

You can turn Churro off at any time by unsetting RUSTC_WRAPPER, and Cargo goes back to compiling everything itself. To ask what we hold about you, or to have it deleted, email hello@churro.sh.

Changes

If this page changes in a way that matters, the date at the top changes with it. The full history is in the site's source on GitHub.

More