1. Overview
Comment Kro ("we", "us", "our") is committed to protecting your personal data and respecting your privacy. This Privacy Policy describes what personal data we collect, how we use it, and your rights under applicable data protection laws, including the Information Technology Act, 2000 and the Digital Personal Data Protection Act, 2023 (India), as well as the General Data Protection Regulation (GDPR) for users in the European Economic Area, and the California Consumer Privacy Act (CCPA) for California residents.
By using the Platform at commentkro.in, you acknowledge that you have read and understood this Privacy Policy. If you do not agree, please discontinue use of the Platform.
2. Data We Collect
We collect the following categories of personal data:
2.1 Account Data
When you register, we collect your name, email address, password (stored as a hashed value), and profile information you choose to provide. If you sign in with Google, Google shares your name, email address and profile picture with us.
2.2 Payment Data
When you subscribe to a paid plan or purchase the ₹9 VIP Pre-Registration pass, payment transactions are processed securely by our authorized payment gateway (Razorpay). The ₹9 VIP pass fee is non-refundable as it guarantees your priority early-access reservation and locked 3-month promotional pricing. We do not store raw credit/debit card numbers or UPI PINs on our servers.
For the VIP Pre-Registration pass we also collect your WhatsApp number, which we use to send you your pass and launch updates.
2.3 Meta / Instagram Account Data
When you connect your Instagram professional account through Instagram's login (Meta OAuth), we receive:
- Your Instagram account ID, username, name and profile picture.
- An access token for the account, which we store encrypted (AES-256-GCM).
- Your posts' IDs, captions, thumbnails and links, which we show in the post picker. We store only the IDs of the posts you pick.
- For people who interact with your automations: their Instagram-scoped ID, their username, the text of their comment or message, and the DMs and replies our automations send them.
2.4 Automation & Usage Data
We store the keyword rules, DM templates, and automation configurations you create. We also log automation activity, including which comments matched a keyword, whether a DM was sent, and the timestamp of each event.
2.5 Technical & Log Data
We automatically collect IP addresses, browser type, device identifiers, referring URLs, pages visited, and timestamps when you use the Platform. This data is used for security monitoring, debugging, and analytics.
2.6 Customer Support & Ticket Data
When you contact support or submit a help ticket, we collect your name, email, WhatsApp number, description of your concern, and any optional screenshots you attach. This information is used solely to investigate your issue and reach back out to you.
3. How We Use Your Data
We process your personal data for the following purposes and legal bases:
| Purpose | Legal Basis |
|---|---|
| Provide and operate the Platform | Performance of contract |
| Process payments and manage subscriptions | Performance of contract |
| Send transactional emails (account, alerts) | Performance of contract |
| Execute Instagram automation on your behalf | Performance of contract |
| Improve and develop Platform features | Legitimate interests |
| Detect and prevent fraud or abuse | Legitimate interests |
| Comply with legal obligations | Legal obligation |
| Send marketing communications (with consent) | Consent |
| Analytics and performance monitoring | Legitimate interests |
4. Meta / Instagram Data
Our Platform uses the Meta Graph API. The use of data obtained from Meta's APIs is governed by Meta's Platform Policy in addition to this Privacy Policy. Specifically:
- We access your Instagram data only to the extent necessary to provide the automation services you have configured.
- Access tokens are stored encrypted (AES-256-GCM) in our database and are used solely to send DMs and read comment webhooks on your behalf.
- We do not sell, rent, or share data received from Meta APIs with third parties for advertising purposes.
- Comment data (including commenter usernames and comment text) is retained only as long as necessary to process automation events and for your review in the contacts/analytics dashboard.
- You can disconnect Instagram at any time in Settings → Connected accounts. This deletes our access token for that account immediately and stops its automations.
How to delete your data:
- Delete your account yourself: go to Settings → General → Delete account. This deletes your Comment Kro account and everything linked to it straight away.
- Remove Comment Kro from Instagram: in the Instagram app, go to Settings and activity → Website permissions → Apps and websites, select Comment Kro, then Remove. Meta tells us, and we delete everything we received through that account straight away: the access token, the account's profile details, its automations, and its message logs and leads. If you also ask Meta to delete your data, Meta shows you a confirmation code that you can check on our data deletion page.
- Email us: as an alternative, email support@commentkro.in from the email address on your account. We delete your data within 30 days and confirm by email.
A few records are kept for a set time afterwards, such as payment records, which the law requires us to keep (see Data Retention). Step-by-step instructions are on our data deletion page.
7. Data Retention
We retain your personal data only for as long as necessary for the purposes described in this Policy:
- Account Data: Kept while your account exists. Deleted straight away when you delete your account in Settings, or within 30 days of a deletion request by email.
- Message Logs: Records of DMs and replies sent by your automations are deleted automatically 90 days after they are created.
- Leads: Kept while your account and that Instagram connection exist, and deleted with them.
- Instagram Access Tokens: Deleted immediately when you disconnect Instagram, and automatically 7 days after they expire.
- Deletion Request Records: The confirmation code and status of a deletion request are kept for 180 days.
- Payment Records: Retained for 7 years as required by Indian accounting and tax laws.
- Server Logs: Retained for 90 days for security monitoring and debugging.
You may request early deletion of your personal data subject to our legal retention obligations (see Your Rights below).
8. Security
We implement industry-standard technical and organisational measures to protect your personal data, including:
- TLS/HTTPS encryption for all data in transit.
- AES-256-GCM encryption for sensitive data at rest (including Meta access tokens).
- Bcrypt hashing for passwords; raw passwords are never stored.
- JWT authentication with short-lived access tokens (15 minutes) and secure refresh token rotation (7 days).
- Role-based access controls limiting employee access to personal data.
- Regular security reviews and penetration testing.
While we take all reasonable steps to protect your data, no system is completely secure. In the event of a personal data breach that poses a high risk to your rights and freedoms, we will notify you as required by applicable law.
9. Your Rights
Depending on your jurisdiction, you may have the following rights regarding your personal data:
9.1 For All Users
- Access: Request a copy of the personal data we hold about you.
- Correction: Request correction of inaccurate or incomplete data.
- Deletion: Request deletion of your personal data ("right to be forgotten"), subject to legal retention obligations.
- Portability: Receive your data in a structured, machine-readable format.
- Objection: Object to processing based on legitimate interests.
- Withdraw Consent: Withdraw consent for consent-based processing (e.g., marketing emails) at any time.
9.2 California Residents (CCPA)
California residents have the right to know what personal information is collected, to opt out of the sale of personal information (we do not sell personal information), and to non-discrimination for exercising these rights.
9.3 EEA/UK Residents (GDPR)
EEA and UK residents have the additional right to lodge a complaint with a supervisory authority and to restrict processing in certain circumstances.
To exercise any of these rights, email us at support@commentkro.in. We will respond within 30 days. We may need to verify your identity before processing your request.
11. Children's Privacy
The Platform is not directed to individuals under the age of 18 ("children"). We do not knowingly collect personal data from children. If you are a parent or guardian and believe your child has provided us with personal data without your consent, please contact us immediately at support@commentkro.in and we will take steps to delete such information.
12. Changes to This Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or for other operational reasons. We will notify you of material changes by:
- Posting the updated Policy on this page with a revised "Last Updated" date.
- Sending an email notification to the address associated with your account.
- Displaying a prominent notice on the Platform dashboard.
Your continued use of the Platform after the effective date of any changes constitutes your acceptance of the updated Policy. If you disagree with the changes, you must stop using the Platform and may request account deletion.
13. Contact Us
For any privacy-related questions, requests, or concerns, please contact us:
We aim to respond to all legitimate requests within 30 calendar days. For complex requests, we may extend this to 60 days and will notify you accordingly.
Also see
Terms of Service