Last updated: July 31, 2026
Daniel James Dupont, carrying on business as CommentProtect ("CommentProtect", "we", "us", or "our"), operates the service from Canada and is the data controller, where that term applies, for the personal data described in this policy.
Questions? Email support@commentprotect.com.
Data We Collect
- Account data: name, email address, mailbox-verification status, versioned Terms and Privacy acceptance, Facebook user ID, role, and preferred language.
- Access-request data: name, work email, company, estimated volume, Page count, use case, consent record, campaign or verified partner attribution, and non-secret approval delivery status.
- Connected pages: page IDs, names, usernames, and encrypted page access tokens.
- Content: comments, replies, and related moderation metadata retrieved through Meta APIs for comment-review workflows.
- Usage analytics: action counts, processing metrics, response times, app page views, interaction events, diagnostic errors, and audit logs.
- Billing metadata: plan tier, Stripe customer ID, and subscription state. Card details are not stored.
- Cookies: session cookies for authentication and security purposes.
How We Use Data
- Deliver core features including comment-review workflows, moderation, bulk actions, AI replies, and analytics.
- Provide AI and translation services using anonymized snippets where possible.
- Send transactional emails such as digests, usage warnings, and GDPR notifications.
- Review, respond to, and measure controlled-access requests.
- Improve reliability and usability through auditing, logging, product analytics, and aggregated performance metrics.
Processors and Service Providers
CommentProtect engages the following processors to provide specific parts of the service:
- Amazon Web Services (AWS): Transactional email delivery and support email processing, including the storage and queues used for those email workflows.
- OpenAI: AI moderation, comment classification, and reply drafting when AI features are configured and used.
- Google Cloud: Translation of comment text when translation features are configured and used.
CommentProtect also exchanges data with Meta Platforms through Facebook and Instagram OAuth and Graph APIs, uses Stripe for billing, invoicing, tax receipts, and payment dispute handling, and uses Google Analytics to measure public website traffic and conversion events. Those providers may also process information under their own terms and privacy policies.
We never sell data to advertisers or unrelated third parties.
Data Storage and Security
- Access tokens are encrypted with AES-256-GCM and decrypted only for live API calls.
- Infrastructure is hosted in hardened cloud environments with strict RBAC controls.
- Hidden comments remain hidden on Facebook or Instagram even if you cancel service.
- Stripe handles payment data and maintains PCI-DSS compliance.
Your Rights
- Right to Access: Request a copy of your data through the authenticated
/gdprportal. - Right to Erasure: Request deletion at
/gdpr. Verified requests are executed within 7 days. - Right to Portability: Export structured JSON or CSV files for transfer to another provider.
- Right to Object: Email support to pause processing or AI features.
- Right to Rectification: Update account information on the settings pages anytime.
Data Retention
- Comments, replies, and related moderation records remain as long as the account stays active.
- Hidden comments stay hidden across Facebook and Instagram even after cancellation.
- Deletion requests are processed within 7 days of verification, then purged from backups within 30 days.
- Unconfirmed controlled-access submissions expire after 24 hours and never enter the owner queue. Mailbox-confirmed requests remain in the private owner queue while we assess or follow up. You may ask support to export, correct, or delete a confirmed request even if you never create an account.
- Expired or consumed email-verification capabilities are removed by nightly cleanup. Expired access-approval delivery metadata is retained for up to 30 additional days for troubleshooting and audit, then removed.
Cookies and Tracking
We use essential cookies for authentication and CSRF protection. Google Analytics may use cookies or similar identifiers on public website pages to measure traffic, referrers, and conversion events. No Meta Pixel or retargeting pixels are embedded.
If you arrive through a partner's referral link, we set a signed affiliate referral cookie (up to 90 days, configurable) containing a pseudonymous click identifier so we can credit the referring partner if you later subscribe. Referral click records store only hashed network identifiers, never your raw IP address, and partners see referred customers only as pseudonymous labels — never names or emails. If your account is deleted, referral records are anonymized while commission accounting records are retained as required by law.
Children's Privacy
CommentProtect is not intended for children under 13. We do not knowingly collect children's personal data.
Changes to this Policy
Material updates will be announced via email and posted here. Continued use after changes indicates consent.
Contact
Contact Daniel James Dupont, carrying on business as CommentProtect, by emailing support@commentprotect.com or use the GDPR portal to request access, portability, objection, or deletion.