Privacy Policy
Last updated: 14 August 2026
This policy describes what Commentrs collects, why we collect it, who else it reaches, how long we keep it, and what you can do about it. It describes the system as it is actually built. Where a number matters — a retention window, a cap — the number is stated here and the screen that applies it shows the same number.
The short version. We collect what the product needs to work: an email address to sign you in, a birth date to check you are old enough, what you post, and how your posts perform. We do not sell personal data. You can download your data or schedule your account for deletion yourself, from inside the app, without asking anyone.
1. Who is responsible
Commentrs operates this platform and decides how the data described here is used. Contact details for privacy requests, and the identity of the operating legal entity, are published at Support inside the app; a support ticket is the channel we monitor and the one that reaches a person.
2. What we collect
2.1 What you give us
- Account. Email address and password (stored only as a hash by our authentication provider, never in readable form), handle, display name, bio and avatar.
- Birth date. Required at signup to enforce the minimum age of 13. See section 7.
- Content. Videos, photo carousels, sounds, stories, live broadcasts, comments, direct messages and group messages.
- Settings. Your privacy, content, notification and region preferences, muted words, blocks and mutes.
- Applications and claims. Business account applications, copyright claims and the evidence documents attached to them, support tickets, reports and appeals.
2.2 What is generated as you use the platform
- Performance data. Views, unique viewers, watch time, completed plays, likes, traffic source and approximate viewer country, per clip and per account.
- Wallet activity. Coms and Diamond balances, purchases, tips sent and received, promotions bought, and withdrawal records.
- Safety signals. The outcome of the automated checks in section 4, reports filed against content, warnings, and your account standing score.
- Technical data. IP address, approximate region derived from it, device and browser characteristics, and push notification subscriptions.
2.3 What we deliberately do not do
- We do not sell personal data, and we do not share it with data brokers.
- We never tell a creator who watched. Viewing is anonymous to the creator, to other users and in every export. The only viewer identity a creator sees is the list of accounts that liked a video, which is a public act.
- Small audiences are suppressed, not rounded. Demographic breakdowns hide any bucket below five people, because a breakdown of a small audience identifies individuals.
- We do not store card numbers or bank details. Payment credentials are entered on the payment provider's own pages and never reach our servers or our database.
3. Why we use it
| Purpose | Data used | Basis (GDPR) |
|---|---|---|
| Running your account and delivering the feed, messages and live streams | Account, content, settings | Performance of a contract |
| Age assurance | Birth date, hashed IP | Legal obligation |
| Payments, Coms purchases and creator payouts | Wallet activity, processor identifiers | Performance of a contract |
| Safety, moderation and fraud prevention | Content, safety signals, technical data | Legitimate interests; legal obligation |
| Ranking and recommending content | Performance data, region, interaction history | Legitimate interests |
| Notifications you have switched on | Push subscription, notification preferences | Consent |
Where the basis is consent — push notifications, and the camera and microphone permissions used for recording and live streaming — you can withdraw it at any time in Settings or in your browser's site settings, without losing access to the rest of the platform.
4. Automated checks
Some decisions are taken automatically, because a person cannot review every upload before it is seen:
- Uploads pass an automated safety review. A clip is visible to you immediately and to others once it passes.
- Comments containing terms blocked for your region, or terms a creator has filtered, are refused as they are written rather than hidden afterwards.
- Copyright evidence submitted with a claim is checked automatically against three separate questions: is the document real proof, does it name the claimant, and does it cover the work.
- Spam, bot activity and VPN or proxy use are detected automatically and may lead to review or suspension.
These checks use a third-party AI model (see section 5). Every automated outcome can be appealed to a person, appeals are free whatever the result, and the reason for the decision is stated rather than withheld. Your account standing, every warning on it, and what each one was for are shown at Settings → Account standing.
5. Who else processes it
We use a small number of service providers. Each receives only what its function requires, and none of them is permitted to use your data for their own purposes.
| Provider | Function | What it receives |
|---|---|---|
| Supabase | Database, authentication, file storage, realtime | Account, content, settings, wallet — the primary data store |
| Netlify | Website hosting and content delivery | Request metadata, including IP address |
| Polar | Payment processing for Coms, Pro and promotions | Payment details, entered on Polar's own pages; email address |
| LiveKit | Live video and audio transport | Stream audio/video and connection metadata while broadcasting |
| Google (Gemini) | Automated content, copyright and support checks | The specific content or document being checked |
| Browser push services | Delivering notifications when the app is closed | An encrypted payload they cannot read, plus your subscription endpoint |
These providers operate internationally, so your data may be processed outside your country, including in the United States. Transfers out of the EEA and the UK rely on the European Commission's Standard Contractual Clauses.
6. What other people can see
- Public by default: your handle, display name, avatar, bio, follower and following counts, public posts and the comments you leave on them.
- Private posts are served through short-lived signed links and are not readable by other users.
- Direct messages are visible to the participants and, where a message is reported, to the reviewer handling that report.
- Business lead forms: anything you submit to one is readable by that business and by the team members it has granted the "leads" permission. Deleting a lead form does not delete submissions already collected.
7. Age
You must be at least 13 years old to use Commentrs. The platform is not directed at children under 13 and we do not knowingly collect their personal data.
Signup asks for a birth date. If the date entered is under 13, the attempt is recorded against a hashed fingerprint of the device and network so the same visitor cannot simply restate their age to get through. We store a hash computed with a per-installation secret, not the IP address itself, so a copy of that table is not a list of IP addresses. It is an age gate that asks nobody for identity documents.
If you believe a child under 13 has created an account, report it from Support and we will remove it.
8. How long we keep it
- While your account is open: for as long as you keep it, since it is the account.
- After you delete your account: 30 days, then permanent erasure. See section 9.
- Content archived on an upheld copyright claim: deleted after 3 days, unless the uploader objects, which freezes the clock while a person reviews it.
- Transaction records: 7 years, which is the longest retention the tax authorities we operate under require. Read section 8.1 — after your account is deleted these records no longer contain your name, your email address or your handle.
- Moderation records: 12 months after your account is deleted, then erased automatically. Longer only for the two categories where the law requires a referral record to survive — content involving children, and terrorism — and those are retained to the period the relevant authority specifies, not indefinitely. Read section 8.2 for what a retained moderation record actually consists of, which is not a profile of you.
8.1 What we do so that a deleted account cannot be leaked
There is a real problem underneath this section and it deserves stating plainly rather than being hidden behind “as required by law”. If we keep financial and moderation records after you leave, then a future breach of this company exposes data about a person who is no longer a user and cannot do anything about it. Deleting your account would not protect you from our mistake. That is a fair criticism and the answer is not to promise better security; it is to make sure the retained records are not worth stealing.
So deletion does not merely stop at the financial rows. It rewrites them. At the end of the 30 days we pseudonymise every record that has to survive: your name, email address, handle, profile text, IP addresses, device identifiers and payment-method details are erased from them, and what remains is an opaque internal reference plus the facts accounting law actually asks for — the amount, the currency, the date, the tax jurisdiction and the invoice number.
This is the whole trick, and it works because tax law requires the transaction, not the taxpayer’s social media profile. A revenue authority auditing us needs to see that a payment of a given size happened on a given date in a given jurisdiction and was accounted for. It does not need to know which handle made it. A leak of the pseudonymised ledger therefore discloses a list of amounts and dates attached to reference numbers that resolve to nobody, because the table that could resolve them was deleted with your account.
Two limits on that promise, because a policy that overclaims here is worse than one that does not claim at all. First, if a specific payment is under an open dispute, chargeback, fraud investigation or legal order when you delete, that one record keeps its identifying details until the matter closes — we cannot answer a chargeback about a payment we can no longer identify — and it is pseudonymised as soon as it does. Second, your payment provider keeps its own records under its own policy; we do not control them, and deleting your Commentrs account has no effect on what Polar or your bank holds.
8.2 What a retained moderation record is, and what it can never do
The second fair criticism is about starting again: if we remember the device and the identifiers behind a removed account, then you can never open a genuinely fresh one, and we could quietly hold your past against a new account you open years later.
What a retained moderation record contains after deletion is a salted one-way hash and nothing else — no address, no device string, no email, no readable identifier of any kind. The salt is held separately from the hashes. A hash of that shape can answer exactly one question, “is this the same value as one on the list”, and it cannot be read backwards into an identity, cannot be joined to anything on another platform, and cannot be assembled into a profile of a person. If it leaks, it leaks a column of meaningless strings.
We also bind what that answer may be used for:
- Only to enforce a live permanent ban. A match blocks the creation of an account by someone who is currently permanently removed for the reasons in section 6.3 of the Terms — child safety, terrorism, attacks on our systems, fraud. Nothing else produces a retained hash at all: an ordinary strike, a suspension that has expired, a refused copyright claim and a closed report leave nothing behind once the account is gone.
- Never to grade a new account. A new account never starts with reduced standing, reduced reach, a lower ranking or hidden restrictions because of a hash match. There is no shadow score. Either the account is blocked outright, with a reason, and you can appeal it — or it is treated as what it is, a new account.
- Never for advertising, ranking or recommendation. This data is not available to those systems and is not in the same store as them.
- It expires. 12 months from deletion for everything except the two legally mandated categories above. “While relevant to platform safety” used to be the rule here, and an open-ended condition that we ourselves assess is not a retention period at all.
Records that outlive an account live in a restricted store that ordinary staff tooling cannot query, and each access is logged and attributable. If you want to know whether anything at all is retained about you after a deletion, ask at Support — we will tell you, and we will tell you when it expires.
9. Your rights, and the buttons that exercise them
Depending on where you live you have rights under the GDPR, the UK GDPR, the CCPA/CPRA or comparable law: access, correction, deletion, portability, restriction, objection, and the right not to be discriminated against for exercising them. Two of those are wired directly into the product, so you do not have to ask us and wait:
-
Export — Settings → Data. Downloads a JSON
archive assembled on the server: your account details and settings, your posts, your
comments, the messages you sent, who you follow and who follows you, and your blocks,
mutes and muted words. It contains what is yours — not everything the platform
knows, because that would include other people's messages to you, which are data about
them.
To prevent client memory issues and API abuse, exports are capped at 5,000 items per section — the most recent 5,000 comments and the most recent 5,000 messages. Both halves of that are real. An account with 200,000 comments produces an archive the browser has to hold in memory to hand you as a file, and the tab dies before the download starts; and an uncapped export endpoint is a way for anyone with an account to make the server assemble an unbounded amount of data on demand, repeatedly. The cap is on how much arrives in one file, not on what you are entitled to: if you need everything, ask at Support and we will produce the complete archive by hand. - Deletion — Settings → Danger zone. Schedules your account for permanent deletion in 30 days and hides it immediately: to everyone else you are already gone. Your profile, videos, comments, messages, conversations, Coms balance and badges are then erased, and any open marketplace listing is cancelled at once.
Signing back in during those 30 days cancels the deletion. Coming back is the undo — there is no separate form to fill in and nobody to email. After 30 days the erasure is permanent and cannot be reversed by us or by you.
One exception exists: an account that other accounts are attached to cannot delete itself while they are alive, because they have no password of their own and deleting the only key would silently orphan them. Delete or hand those over first; the app says so at the time.
What deletion cannot reach is stated in section 8, not buried. Two categories survive it — pseudonymised financial records and, only for permanent removals, a one-way hash — and sections 8.1 and 8.2 say exactly what each contains, how long it lasts, and what it is forbidden from being used for.
For anything not covered by those two buttons — correction, restriction, objection, or an export larger than the cap — open a ticket at Support. We answer within 30 days. If you are in the EEA or the UK you may also complain to your national data protection authority.
10. Security
Access to data is enforced in the database itself with row-level security, so a rule about who may read a row is applied by the database rather than by whichever screen happens to request it. Passwords are stored only as hashes. Private media is served through short-lived signed URLs. Payment credentials never touch our servers. Gift API keys are stored hashed, and are shown once at creation and never again.
No system is perfectly secure. Where a breach is likely to result in a high risk to you, we will notify you and the relevant regulator within the deadlines the law sets.
11. Cookies and local storage
We use browser storage for the things the app cannot work without: your login session, your theme and language choice, and a service worker cache that lets the app open offline. We do not use third-party advertising or cross-site tracking cookies, which is why you are not asked to dismiss a consent banner on arrival.
12. Changes to this policy
Minor corrections take effect on publication. For a material change we give at least 3 days' notice by in-app notification, push notification or email before it takes effect, matching the notice period in the Terms of Service.