Privacy Policy
This Privacy Policy explains how Commenta collects, uses, shares, and protects personal data when you browse the website, create an account, connect Google or YouTube services, subscribe to a plan, or use the product.
Effective date: March 12, 2026
Data Controller and Business Identity
The controller responsible for personal data processed through Commenta is Kandefer Group Ltd. Şti., located at Kayseri, Türkiye. Privacy questions and requests may be sent to contact@commenta.ai.
What Data We Collect
Depending on how you use the Service, we may collect:
- account identifiers such as name, email address, profile image, and login data;
- workspace, channel, and subscription identifiers and configuration settings;
- YouTube channel metadata, comment threads, reply drafts, and related activity logs;
- support communications, feedback, and administrative records; and
- security, device, browser, IP, and usage information needed to operate the Service.
Google and YouTube OAuth and API Data Use
When you connect Google or YouTube services, Commenta may access the account profile, authorized channel information, comment data, and permissions required to authenticate your account, sync comments, analyze engagement, and publish replies if you instruct the Service to do so.
Data received from Google or YouTube APIs is used only to provide the features you request, maintain the connected account relationship, secure the Service, and improve the user-facing functionality of the product consistent with the permissions you grant and the applicable Google and YouTube platform terms.
AI-Generated Reply Processing
To create reply drafts, summaries, moderation signals, or audience analysis, the Service may send relevant inputs such as comment text, channel context, configuration choices, and safety metadata to AI service providers.
AI-generated outputs can be inaccurate or incomplete. You remain responsible for deciding whether to use, edit, review, or publish any generated content.
Payment and Subscription Metadata
If you purchase a paid plan, Paddle, acting as merchant of record, may provide the Service with subscription, transaction, invoice, payment status, tax, and customer metadata needed to manage your plan and account status.
The Service does not need to store full payment card details to provide the core product.
Cookies and Usage Data
Commenta uses essential cookies and similar technologies for authentication, security, consent, and product functionality. Optional analytics or similar measurement tools, if enabled, are handled according to your consent choices and local requirements.
More detail is available in the Cookies Policy.
Purposes of Processing
We process personal data to:
- create and manage user accounts and connected channel workspaces;
- sync comments, generate and publish replies, and provide analytics or insights;
- process subscriptions, manage billing status, and provide customer support;
- detect fraud, abuse, errors, and security incidents;
- maintain, troubleshoot, and improve the Service; and
- meet contractual, legal, regulatory, and recordkeeping obligations.
Legal Bases
Depending on your location, the legal bases for processing may include performance of a contract with you, legitimate interests in operating and securing the Service, consent where required, and compliance with legal obligations.
Sharing with Processors and Subprocessors
We may share data with service providers and subprocessors that help operate the Service, such as hosting and infrastructure vendors, authentication and account providers, AI processing providers used to generate or analyze content, such as OpenAI, Paddle for billing operations, Google and YouTube for connected-account functionality, and security, support, or compliance vendors.
We may also disclose information where reasonably necessary to enforce our terms, protect rights and safety, or comply with law or a valid legal request.
Subprocessors
For a list of infrastructure providers that may process customer data on our behalf, see the Subprocessors page.
Retention
We retain data for as long as it is needed to provide the Service, maintain your account, support legitimate business operations, resolve disputes, investigate abuse, comply with law, and preserve required financial or audit records.
Retention periods may differ by data type and operational purpose, and some data may remain in backups or archived systems for a limited period after deletion.
User Rights
Subject to applicable law, you may have rights to request access, correction, deletion, portability, restriction, or objection to processing, and to withdraw consent where processing depends on consent.
We may ask you to verify your identity before acting on a request and may deny or limit a request where the law permits.
Account Deletion and Disconnection Handling
If you disconnect Google or YouTube access, the Service should no longer initiate new sync or reply activity for the disconnected account after the disconnect is processed.
If you delete your account, active subscription management may also require cancellation through the applicable billing tools, and certain records may be retained where needed for billing reconciliation, fraud prevention, legal compliance, or internal audit purposes.
International Transfers
Commenta is a global SaaS service and may use providers that process data in countries other than your own. Where required, we rely on contractual, technical, or organizational safeguards that are appropriate to the transfer.
Security
We use reasonable technical and organizational measures designed to protect personal data. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
Children and Minors
The Service is not directed to children and should not be used by anyone who cannot legally authorize the use of the Service in their jurisdiction. If you believe a child has provided personal data without authorization, contact contact@commenta.ai.
Policy Changes
We may update this Privacy Policy from time to time. If we make material changes, we may provide additional notice through the Service or by other appropriate means. The updated version will become effective on the date shown at the top of this page.
Contact Details
Privacy requests and notices may be sent to Kandefer Group Ltd. Şti., Kayseri, Türkiye, or contact@commenta.ai.