Privacy Policy

Last updated: 14 August 2026

This policy describes what Commentrs collects, why we collect it, who else it reaches, how long we keep it, and what you can do about it. It describes the system as it is actually built. Where a number matters — a retention window, a cap — the number is stated here and the screen that applies it shows the same number.

The short version. We collect what the product needs to work: an email address to sign you in, a birth date to check you are old enough, what you post, and how your posts perform. We do not sell personal data. You can download your data or schedule your account for deletion yourself, from inside the app, without asking anyone.

1. Who is responsible

Commentrs operates this platform and decides how the data described here is used. Contact details for privacy requests, and the identity of the operating legal entity, are published at Support inside the app; a support ticket is the channel we monitor and the one that reaches a person.

2. What we collect

2.1 What you give us

2.2 What is generated as you use the platform

2.3 What we deliberately do not do

3. Why we use it

Purpose Data used Basis (GDPR)
Running your account and delivering the feed, messages and live streams Account, content, settings Performance of a contract
Age assurance Birth date, hashed IP Legal obligation
Payments, Coms purchases and creator payouts Wallet activity, processor identifiers Performance of a contract
Safety, moderation and fraud prevention Content, safety signals, technical data Legitimate interests; legal obligation
Ranking and recommending content Performance data, region, interaction history Legitimate interests
Notifications you have switched on Push subscription, notification preferences Consent

Where the basis is consent — push notifications, and the camera and microphone permissions used for recording and live streaming — you can withdraw it at any time in Settings or in your browser's site settings, without losing access to the rest of the platform.

4. Automated checks

Some decisions are taken automatically, because a person cannot review every upload before it is seen:

These checks use a third-party AI model (see section 5). Every automated outcome can be appealed to a person, appeals are free whatever the result, and the reason for the decision is stated rather than withheld. Your account standing, every warning on it, and what each one was for are shown at Settings → Account standing.

5. Who else processes it

We use a small number of service providers. Each receives only what its function requires, and none of them is permitted to use your data for their own purposes.

Provider Function What it receives
Supabase Database, authentication, file storage, realtime Account, content, settings, wallet — the primary data store
Netlify Website hosting and content delivery Request metadata, including IP address
Polar Payment processing for Coms, Pro and promotions Payment details, entered on Polar's own pages; email address
LiveKit Live video and audio transport Stream audio/video and connection metadata while broadcasting
Google (Gemini) Automated content, copyright and support checks The specific content or document being checked
Browser push services Delivering notifications when the app is closed An encrypted payload they cannot read, plus your subscription endpoint

These providers operate internationally, so your data may be processed outside your country, including in the United States. Transfers out of the EEA and the UK rely on the European Commission's Standard Contractual Clauses.

6. What other people can see

7. Age

You must be at least 13 years old to use Commentrs. The platform is not directed at children under 13 and we do not knowingly collect their personal data.

Signup asks for a birth date. If the date entered is under 13, the attempt is recorded against a hashed fingerprint of the device and network so the same visitor cannot simply restate their age to get through. We store a hash computed with a per-installation secret, not the IP address itself, so a copy of that table is not a list of IP addresses. It is an age gate that asks nobody for identity documents.

If you believe a child under 13 has created an account, report it from Support and we will remove it.

8. How long we keep it

8.1 What we do so that a deleted account cannot be leaked

There is a real problem underneath this section and it deserves stating plainly rather than being hidden behind “as required by law”. If we keep financial and moderation records after you leave, then a future breach of this company exposes data about a person who is no longer a user and cannot do anything about it. Deleting your account would not protect you from our mistake. That is a fair criticism and the answer is not to promise better security; it is to make sure the retained records are not worth stealing.

So deletion does not merely stop at the financial rows. It rewrites them. At the end of the 30 days we pseudonymise every record that has to survive: your name, email address, handle, profile text, IP addresses, device identifiers and payment-method details are erased from them, and what remains is an opaque internal reference plus the facts accounting law actually asks for — the amount, the currency, the date, the tax jurisdiction and the invoice number.

This is the whole trick, and it works because tax law requires the transaction, not the taxpayer’s social media profile. A revenue authority auditing us needs to see that a payment of a given size happened on a given date in a given jurisdiction and was accounted for. It does not need to know which handle made it. A leak of the pseudonymised ledger therefore discloses a list of amounts and dates attached to reference numbers that resolve to nobody, because the table that could resolve them was deleted with your account.

Two limits on that promise, because a policy that overclaims here is worse than one that does not claim at all. First, if a specific payment is under an open dispute, chargeback, fraud investigation or legal order when you delete, that one record keeps its identifying details until the matter closes — we cannot answer a chargeback about a payment we can no longer identify — and it is pseudonymised as soon as it does. Second, your payment provider keeps its own records under its own policy; we do not control them, and deleting your Commentrs account has no effect on what Polar or your bank holds.

8.2 What a retained moderation record is, and what it can never do

The second fair criticism is about starting again: if we remember the device and the identifiers behind a removed account, then you can never open a genuinely fresh one, and we could quietly hold your past against a new account you open years later.

What a retained moderation record contains after deletion is a salted one-way hash and nothing else — no address, no device string, no email, no readable identifier of any kind. The salt is held separately from the hashes. A hash of that shape can answer exactly one question, “is this the same value as one on the list”, and it cannot be read backwards into an identity, cannot be joined to anything on another platform, and cannot be assembled into a profile of a person. If it leaks, it leaks a column of meaningless strings.

We also bind what that answer may be used for:

Records that outlive an account live in a restricted store that ordinary staff tooling cannot query, and each access is logged and attributable. If you want to know whether anything at all is retained about you after a deletion, ask at Support — we will tell you, and we will tell you when it expires.

9. Your rights, and the buttons that exercise them

Depending on where you live you have rights under the GDPR, the UK GDPR, the CCPA/CPRA or comparable law: access, correction, deletion, portability, restriction, objection, and the right not to be discriminated against for exercising them. Two of those are wired directly into the product, so you do not have to ask us and wait:

Signing back in during those 30 days cancels the deletion. Coming back is the undo — there is no separate form to fill in and nobody to email. After 30 days the erasure is permanent and cannot be reversed by us or by you.

One exception exists: an account that other accounts are attached to cannot delete itself while they are alive, because they have no password of their own and deleting the only key would silently orphan them. Delete or hand those over first; the app says so at the time.

What deletion cannot reach is stated in section 8, not buried. Two categories survive it — pseudonymised financial records and, only for permanent removals, a one-way hash — and sections 8.1 and 8.2 say exactly what each contains, how long it lasts, and what it is forbidden from being used for.

For anything not covered by those two buttons — correction, restriction, objection, or an export larger than the cap — open a ticket at Support. We answer within 30 days. If you are in the EEA or the UK you may also complain to your national data protection authority.

10. Security

Access to data is enforced in the database itself with row-level security, so a rule about who may read a row is applied by the database rather than by whichever screen happens to request it. Passwords are stored only as hashes. Private media is served through short-lived signed URLs. Payment credentials never touch our servers. Gift API keys are stored hashed, and are shown once at creation and never again.

No system is perfectly secure. Where a breach is likely to result in a high risk to you, we will notify you and the relevant regulator within the deadlines the law sets.

11. Cookies and local storage

We use browser storage for the things the app cannot work without: your login session, your theme and language choice, and a service worker cache that lets the app open offline. We do not use third-party advertising or cross-site tracking cookies, which is why you are not asked to dismiss a consent banner on arrival.

12. Changes to this policy

Minor corrections take effect on publication. For a material change we give at least 3 days' notice by in-app notification, push notification or email before it takes effect, matching the notice period in the Terms of Service.