Privacy Policy

Last updated: February 2025

1. Information We Collect

When you create an account, we collect your name, email address, and password (stored securely using bcrypt hashing). We do not store your password in plain text.

When you use our service, we collect:

  • Campaign data you create (brand name, product descriptions, keywords, target subreddits)
  • AI-generated comments and their posting status
  • Discovered posts from public Reddit and YouTube data
  • Extension authentication tokens for the Chrome extension
  • Usage data such as login times and feature interactions

2. How We Use Your Information

We use the information we collect to:

  • Provide and maintain the CommentFlow service
  • Generate AI-powered comments based on your campaign settings
  • Discover relevant posts on Reddit and YouTube matching your keywords
  • Authenticate your Chrome extension for auto-posting
  • Send you service-related communications
  • Improve and optimize our platform

3. Data Sharing

We do not sell your personal information. We may share data with:

  • OpenAI — Post titles and content are sent to OpenAI's API to generate comments. This data is processed according to OpenAI's data usage policies.
  • Payment processors — If you subscribe to a paid plan, your payment information is handled by our payment processor (Stripe). We do not store your credit card details.
  • Service providers — We may use third-party services for hosting, analytics, and error tracking.

4. Data Security

We implement industry-standard security measures to protect your data, including encrypted passwords, secure HTTPS connections, and access controls. However, no method of electronic storage is 100% secure, and we cannot guarantee absolute security.

5. Data Retention

We retain your account data for as long as your account is active. Campaign data, discovered posts, and generated comments are retained for the duration of your subscription. You can delete your account and associated data by contacting us at support@commentflow.io.

6. Your Rights

Depending on your jurisdiction, you may have the right to:

  • Access the personal data we hold about you
  • Request correction of inaccurate data
  • Request deletion of your data
  • Object to or restrict processing of your data
  • Export your data in a portable format

To exercise these rights, contact us at support@commentflow.io.

7. Cookies

We use essential cookies for authentication and session management. We use localStorage to save your theme preference. We do not use third-party tracking cookies.

8. Third-Party Platforms

CommentFlow interacts with Reddit and YouTube through their public APIs. Your use of these platforms is subject to their respective privacy policies and terms of service. CommentFlow does not access your Reddit or YouTube account credentials — the Chrome extension operates within your existing browser session.

9. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of significant changes by email or through a notice on our website. Your continued use of the service after changes constitutes acceptance of the updated policy.

10. Contact Us

If you have questions about this Privacy Policy, contact us at support@commentflow.io.