Skip to content
CommentKro
Legal

Privacy policy

Last updated: This Privacy Policy explains how Comment Kro collects, uses, and protects your personal data when you use commentkro.in.

1. Overview

Comment Kro ("we", "us", "our") is committed to protecting your personal data and respecting your privacy. This Privacy Policy describes what personal data we collect, how we use it, and your rights under applicable data protection laws, including the Information Technology Act, 2000 and the Digital Personal Data Protection Act, 2023 (India), as well as the General Data Protection Regulation (GDPR) for users in the European Economic Area, and the California Consumer Privacy Act (CCPA) for California residents.

By using the Platform at commentkro.in, you acknowledge that you have read and understood this Privacy Policy. If you do not agree, please discontinue use of the Platform.

2. Data We Collect

We collect the following categories of personal data:

2.1 Account Data

When you register, we collect your name, email address, password (stored as a hashed value), and profile information you choose to provide. If you sign in with Google, Google shares your name, email address and profile picture with us.

2.2 Payment Data

When you subscribe to a paid plan or purchase the ₹9 VIP Pre-Registration pass, payment transactions are processed securely by our authorized payment gateway (Razorpay). The ₹9 VIP pass fee is non-refundable as it guarantees your priority early-access reservation and locked 3-month promotional pricing. We do not store raw credit/debit card numbers or UPI PINs on our servers.

For the VIP Pre-Registration pass we also collect your WhatsApp number, which we use to send you your pass and launch updates.

2.3 Meta / Instagram Account Data

When you connect your Instagram professional account through Instagram's login (Meta OAuth), we receive:

  • Your Instagram account ID, username, name and profile picture.
  • An access token for the account, which we store encrypted (AES-256-GCM).
  • Your posts' IDs, captions, thumbnails and links, which we show in the post picker. We store only the IDs of the posts you pick.
  • For people who interact with your automations: their Instagram-scoped ID, their username, the text of their comment or message, and the DMs and replies our automations send them.

2.4 Automation & Usage Data

We store the keyword rules, DM templates, and automation configurations you create. We also log automation activity, including which comments matched a keyword, whether a DM was sent, and the timestamp of each event.

2.5 Technical & Log Data

We automatically collect IP addresses, browser type, device identifiers, referring URLs, pages visited, and timestamps when you use the Platform. This data is used for security monitoring, debugging, and analytics.

2.6 Customer Support & Ticket Data

When you contact support or submit a help ticket, we collect your name, email, WhatsApp number, description of your concern, and any optional screenshots you attach. This information is used solely to investigate your issue and reach back out to you.

3. How We Use Your Data

We process your personal data for the following purposes and legal bases:

Purposes for which we process your personal data, and the legal basis for each
PurposeLegal Basis
Provide and operate the PlatformPerformance of contract
Process payments and manage subscriptionsPerformance of contract
Send transactional emails (account, alerts)Performance of contract
Execute Instagram automation on your behalfPerformance of contract
Improve and develop Platform featuresLegitimate interests
Detect and prevent fraud or abuseLegitimate interests
Comply with legal obligationsLegal obligation
Send marketing communications (with consent)Consent
Analytics and performance monitoringLegitimate interests

4. Meta / Instagram Data

Our Platform uses the Meta Graph API. The use of data obtained from Meta's APIs is governed by Meta's Platform Policy in addition to this Privacy Policy. Specifically:

  • We access your Instagram data only to the extent necessary to provide the automation services you have configured.
  • Access tokens are stored encrypted (AES-256-GCM) in our database and are used solely to send DMs and read comment webhooks on your behalf.
  • We do not sell, rent, or share data received from Meta APIs with third parties for advertising purposes.
  • Comment data (including commenter usernames and comment text) is retained only as long as necessary to process automation events and for your review in the contacts/analytics dashboard.
  • You can disconnect Instagram at any time in Settings → Connected accounts. This deletes our access token for that account immediately and stops its automations.

How to delete your data:

  • Delete your account yourself: go to Settings → General → Delete account. This deletes your Comment Kro account and everything linked to it straight away.
  • Remove Comment Kro from Instagram: in the Instagram app, go to Settings and activity → Website permissions → Apps and websites, select Comment Kro, then Remove. Meta tells us, and we delete everything we received through that account straight away: the access token, the account's profile details, its automations, and its message logs and leads. If you also ask Meta to delete your data, Meta shows you a confirmation code that you can check on our data deletion page.
  • Email us: as an alternative, email support@commentkro.in from the email address on your account. We delete your data within 30 days and confirm by email.

A few records are kept for a set time afterwards, such as payment records, which the law requires us to keep (see Data Retention). Step-by-step instructions are on our data deletion page.

5. Data Sharing & Third Parties

We do not sell your personal data. We share your data only in the following limited circumstances:

5.1 Service Providers

We use these service providers to run the Platform:

  • MongoDB Atlas (MongoDB, Inc.): our database.
  • Render (Render Services, Inc.): runs our API servers.
  • Cloudflare (Cloudflare, Inc.): DNS and network security for our API.
  • Vercel (Vercel Inc.): hosts this website and provides cookie-free analytics.
  • Resend: sends our transactional emails.
  • Razorpay: processes payments.
  • Google: provides Sign in with Google.

All service providers are contractually bound to process your data only on our instructions and to maintain appropriate security measures.

5.2 Legal Requirements

We may disclose your data if required to do so by law, court order, or governmental authority, or if we believe in good faith that disclosure is necessary to protect our rights, protect your safety or the safety of others, or investigate fraud. See Requests from Public Authorities for how we handle requests from authorities.

5.3 Business Transfers

In the event of a merger, acquisition, or sale of all or substantially all of our assets, your data may be transferred to the acquiring entity, subject to the same privacy protections described in this Policy.

6. Requests from Public Authorities

If a court, government body, regulator or law enforcement agency asks us for personal data, we:

  • Review every request for legality and validity before we respond.
  • Challenge requests that are unlawful, overbroad or not properly authorised.
  • Disclose only the minimum data needed to answer the request.
  • Document each request and our response.
  • Tell the affected user about the request, unless the law prohibits us from doing so.

7. Data Retention

We retain your personal data only for as long as necessary for the purposes described in this Policy:

  • Account Data: Kept while your account exists. Deleted straight away when you delete your account in Settings, or within 30 days of a deletion request by email.
  • Message Logs: Records of DMs and replies sent by your automations are deleted automatically 90 days after they are created.
  • Leads: Kept while your account and that Instagram connection exist, and deleted with them.
  • Instagram Access Tokens: Deleted immediately when you disconnect Instagram, and automatically 7 days after they expire.
  • Deletion Request Records: The confirmation code and status of a deletion request are kept for 180 days.
  • Payment Records: Retained for 7 years as required by Indian accounting and tax laws.
  • Server Logs: Retained for 90 days for security monitoring and debugging.

You may request early deletion of your personal data subject to our legal retention obligations (see Your Rights below).

8. Security

We implement industry-standard technical and organisational measures to protect your personal data, including:

  • TLS/HTTPS encryption for all data in transit.
  • AES-256-GCM encryption for sensitive data at rest (including Meta access tokens).
  • Bcrypt hashing for passwords; raw passwords are never stored.
  • JWT authentication with short-lived access tokens (15 minutes) and secure refresh token rotation (7 days).
  • Role-based access controls limiting employee access to personal data.
  • Regular security reviews and penetration testing.

While we take all reasonable steps to protect your data, no system is completely secure. In the event of a personal data breach that poses a high risk to your rights and freedoms, we will notify you as required by applicable law.

9. Your Rights

Depending on your jurisdiction, you may have the following rights regarding your personal data:

9.1 For All Users

  • Access: Request a copy of the personal data we hold about you.
  • Correction: Request correction of inaccurate or incomplete data.
  • Deletion: Request deletion of your personal data ("right to be forgotten"), subject to legal retention obligations.
  • Portability: Receive your data in a structured, machine-readable format.
  • Objection: Object to processing based on legitimate interests.
  • Withdraw Consent: Withdraw consent for consent-based processing (e.g., marketing emails) at any time.

9.2 California Residents (CCPA)

California residents have the right to know what personal information is collected, to opt out of the sale of personal information (we do not sell personal information), and to non-discrimination for exercising these rights.

9.3 EEA/UK Residents (GDPR)

EEA and UK residents have the additional right to lodge a complaint with a supervisory authority and to restrict processing in certain circumstances.

To exercise any of these rights, email us at support@commentkro.in. We will respond within 30 days. We may need to verify your identity before processing your request.

10. Cookies & Tracking

We use the following categories of cookies and tracking technologies:

  • Strictly Necessary Cookies: Required for the Platform to function (e.g., session authentication tokens stored in httpOnly cookies). These cannot be disabled.
  • Analytics Cookies: We use Vercel Analytics, which is cookie-free and privacy-preserving by design. No cross-site tracking occurs.

We do not use third-party advertising cookies or tracking pixels. You can control cookie preferences through your browser settings, though disabling strictly necessary cookies will affect Platform functionality.

11. Children's Privacy

The Platform is not directed to individuals under the age of 18 ("children"). We do not knowingly collect personal data from children. If you are a parent or guardian and believe your child has provided us with personal data without your consent, please contact us immediately at support@commentkro.in and we will take steps to delete such information.

12. Changes to This Policy

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. We will notify you of material changes by:

  • Posting the updated Policy on this page with a revised "Last Updated" date.
  • Sending an email notification to the address associated with your account.
  • Displaying a prominent notice on the Platform dashboard.

Your continued use of the Platform after the effective date of any changes constitutes your acceptance of the updated Policy. If you disagree with the changes, you must stop using the Platform and may request account deletion.

13. Contact Us

For any privacy-related questions, requests, or concerns, please contact us:

Company: Comment Kro

Website: commentkro.in

Support Email: support@commentkro.in

Jurisdiction: India

We aim to respond to all legitimate requests within 30 calendar days. For complex requests, we may extend this to 60 days and will notify you accordingly.