Privacy Policy

Last updated: October 24, 2025

1. Introduction

Welcome to CommentFirst ("we," "our," or "us"). We are committed to protecting your personal information and your right to privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website and services (collectively, the "Service").

By using our Service, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree with our policies and practices, please do not use our Service.

2. Information We Collect

2.1 Personal Information

When you register for an account, we collect the following information:

  • Name
  • Email address
  • Google account information (when you sign in with Google)
  • Profile picture (if provided through Google)

2.2 YouTube Data

With your explicit consent, we access and use your YouTube Data through the YouTube API Services to provide our core functionality:

  • Your YouTube channel information and statistics
  • Your video metadata (titles, descriptions, view counts)
  • Comments on your videos and comment thread information
  • Comment reply capabilities on your own videos
  • Channel authentication and access tokens

Important: We only access the minimum YouTube data necessary to provide our Service. We do not store your YouTube credentials. All YouTube data access is done in accordance with the YouTube Terms of Service and Google Privacy Policy.

2.3 Payment Information

Payment processing is handled by Stripe, a third-party payment processor. We do not store your credit card information. Stripe collects and processes your payment information in accordance with their Privacy Policy.

2.4 Usage Data

We automatically collect certain information when you use our Service:

  • IP address
  • Browser type and version
  • Pages visited and time spent
  • Device information
  • Error logs and diagnostic data

3. How We Use Your Information

We use the collected information for the following purposes:

  • Provide and maintain our Service: Including monitoring comments on your videos and posting automated responses on your behalf
  • Process payments: Through our payment processor Stripe
  • Send you updates: About your account, auto-responses, and service changes
  • Improve our Service: Through analytics and user feedback
  • Detect and prevent fraud: To maintain the security of our Service
  • Comply with legal obligations: When required by law

4. YouTube Data Usage and Retention

In compliance with YouTube API Services Terms, we want to be transparent about how we use your YouTube data:

  • We use YouTube data solely to provide automated comment management and response services on your own videos
  • We store only the minimum data necessary (your channel ID, video IDs, comment templates) to fulfill your automated response configurations
  • We do not access or interact with videos from other YouTube channels
  • We do not use YouTube data for advertising or marketing purposes
  • We do not sell or share your YouTube data with third parties
  • You can revoke our access to your YouTube data at any time through your Google Account Permissions

Data Retention: We retain your YouTube data only for as long as necessary to provide our Service or as required by law. When you delete your account or revoke permissions, we delete your YouTube data within 30 days.

5. Data Sharing and Disclosure

We do not sell your personal information. We may share your information only in the following circumstances:

  • Service Providers: We share data with trusted third-party service providers (Google OAuth, Stripe, Vercel, Supabase) who assist in operating our Service
  • Legal Requirements: When required by law, court order, or government regulation
  • Business Transfers: In connection with a merger, sale, or acquisition of our company
  • With Your Consent: When you explicitly authorize us to share your information

6. Data Security

We implement appropriate technical and organizational security measures to protect your personal information:

  • Encryption of data in transit (HTTPS/TLS)
  • Encryption of data at rest in our databases
  • Regular security audits and updates
  • Access controls and authentication mechanisms
  • Monitoring and logging of access to personal data

However, no method of transmission over the internet is 100% secure. While we strive to protect your personal information, we cannot guarantee absolute security.

7. Your Privacy Rights

Depending on your location, you may have the following rights:

  • Access: Request a copy of the personal information we hold about you
  • Correction: Request correction of inaccurate or incomplete data
  • Deletion: Request deletion of your personal information
  • Data Portability: Request transfer of your data to another service
  • Withdraw Consent: Revoke your consent to data processing at any time
  • Object to Processing: Object to our processing of your personal information

To exercise any of these rights, please contact us at firstcomment358@gmail.com.

8. Cookies and Tracking

We use cookies and similar tracking technologies to enhance your experience:

  • Essential Cookies: Required for authentication and security
  • Analytics Cookies: Help us understand how you use our Service
  • Preference Cookies: Remember your settings and preferences

You can control cookies through your browser settings. Note that disabling cookies may affect the functionality of our Service.

9. Third-Party Services

Our Service integrates with third-party services:

We are not responsible for the privacy practices of these third-party services. We encourage you to review their privacy policies.

10. Children's Privacy

Our Service is not intended for users under the age of 13 (or the applicable age of digital consent in your jurisdiction). We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately at firstcomment358@gmail.com.

11. International Data Transfers

Your information may be transferred to and processed in countries other than your country of residence. These countries may have different data protection laws. By using our Service, you consent to the transfer of your information to these countries. We ensure appropriate safeguards are in place to protect your information in accordance with this Privacy Policy.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by:

  • Posting the new Privacy Policy on this page
  • Updating the "Last updated" date
  • Sending you an email notification (for significant changes)

We encourage you to review this Privacy Policy periodically. Your continued use of the Service after changes constitutes acceptance of the updated Privacy Policy.

13. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

Email: firstcomment358@gmail.com

Service Name: CommentFirst

Website: https://comment-first.vercel.app

We will respond to your inquiry within 30 days.

14. Additional Rights for EU and California Residents

For EU Residents (GDPR)

If you are a resident of the European Union, you have additional rights under the General Data Protection Regulation (GDPR), including:

  • Right to lodge a complaint with a supervisory authority
  • Right to restriction of processing
  • Right to object to automated decision-making

For California Residents (CCPA)

If you are a California resident, you have rights under the California Consumer Privacy Act (CCPA), including:

  • Right to know what personal information we collect and how it is used
  • Right to request deletion of personal information
  • Right to opt-out of the sale of personal information (note: we do not sell personal information)
  • Right to non-discrimination for exercising your rights

This Privacy Policy is effective as of October 24, 2025 and applies to all users of CommentFirst.