Commento ("we", "us", "the app") helps YouTube creators understand what their viewers ask about and reply to them. Commento is a YouTube API Services client — it uses the YouTube Data API to read and act on your channel with your consent. This policy explains exactly what user information, including data obtained through the YouTube API ("API Data"), we access, collect, store and use, and why.
What user information and API Data we access and collect
We access and collect only the information below. "API Data" means data we obtain from the YouTube API Services on your behalf.
| Information | Source | Why we access, collect and use it |
| Your Google profile — name, email address, profile picture, Google account ID | Google sign-in (openid email profile scopes) | To create and identify your account. This is the only data plain sign-in uses; no YouTube access is granted at sign-in. |
| Your YouTube channel details (API Data) — channel ID and title | YouTube Data API, only after you choose to "Connect your channel" | To show which channel is connected and to act only on your own channel. |
| Comments and replies on your videos (API Data) | YouTube Data API (commentThreads, comments) | To find, group and answer the questions your viewers repeat, and — with your explicit per-reply approval — to post your reply. |
| Captions/transcripts, titles and descriptions of your videos (API Data) | YouTube Data API (captions, videos, search) | To know which products, places and tools you actually mentioned, so a reply is accurate instead of invented. |
| Public data of any video you scan — public title, description and comments | YouTube Data API, for a YouTube URL you paste | To surface what viewers ask about on that video. |
With your consent we use a single YouTube scope, youtube.force-ssl, to read the captions and metadata of your own videos, read comments on them, and — only with your explicit per-reply approval — post, delete or moderate replies from your account. We never post, edit, delete or moderate anything without you approving it, and we never access any channel other than your own.
What we store
- Your account profile (name, email, profile picture, Google account ID).
- Your scan results — the products/places/tools found, the grouped questions, and the replies drafted for you.
- Your affiliate links, campaigns and the click counts on the tracked short links we generate.
- If you connect YouTube, an OAuth access token and refresh token so we can act on your behalf; you can revoke these any time at myaccount.google.com/permissions, by disconnecting in Settings, or by signing out.
How often we refresh, update and delete API Data
- Refresh cadence. For a connected channel, Commento re-reads your recent videos roughly every 3 hours and checks for new comments to answer roughly every 5 minutes. Each refresh replaces the previously stored data for that video, so what we hold reflects the current state of your channel rather than an ever-growing archive.
- Retention. API Data is retained only while your account is active and only as long as needed to provide the features you see. We do not retain YouTube API Data for longer than the service requires, and we do not use it to build any profile beyond your own account.
- Deletion. When you disconnect your channel in Settings, your stored OAuth tokens and channel link are deleted from our database immediately, which stops all further access. Removing a video removes its stored scan. When you delete your account — or email us to do so — your profile, all stored YouTube API Data (comments, caption-derived products, drafted replies), and OAuth tokens are permanently deleted.
- If you revoke access at myaccount.google.com/permissions, Commento can no longer call the YouTube API for you, and the tokens we hold become inert; disconnecting or deleting your account removes them entirely.
Cookies and storage on your device
Commento stores and accesses a small amount of information on your device. We use it only to keep you signed in, keep the app secure, and remember your preferences — we do not use advertising or cross-site tracking cookies, and we do not allow third parties to place advertising or tracking technology through Commento.
- Essential first-party cookies.
replai_session keeps you signed in (HTTP-only, sent only over HTTPS, SameSite=Lax). replai_oauth_state is a short-lived cookie set only during Google sign-in to protect against cross-site request forgery. The app does not work without these.
- Local storage on your device. We use your browser's local and session storage to remember preferences (such as which notifications you have read, your sync choice and notification toggles) and to briefly cache responses so the app is fast. This stays on your device.
- Google's own cookies. When you sign in with Google or connect YouTube, Google may set its own cookies as part of that sign-in. Google's handling of that data is governed by the Google Privacy Policy.
How we protect your data
We treat your Google and YouTube data (including the OAuth tokens, your videos' comments and captions, and any replies) as sensitive, and protect it with the following measures:
- Encryption in transit. All data moving between your browser, Commento, and Google's APIs is sent over encrypted HTTPS/TLS connections. Commento is served exclusively over HTTPS.
- Encryption at rest. Your data — including OAuth tokens and scan results — is stored in a managed PostgreSQL database that encrypts data at rest (AES-256).
- Restricted access. Only the Commento application, using service credentials, can read this data. It is never exposed publicly, sold, or shared with third parties, and no human accesses your YouTube content except where you explicitly ask us for support.
- Least-privilege scopes. We request only the single YouTube scope needed to read and reply on your own videos, and no access to any channel other than your own.
- Token handling. Your OAuth token is stored solely so Commento can act on your behalf with your approval. You can revoke it at any moment at myaccount.google.com/permissions or by disconnecting in Settings, which immediately stops all access.
What we do NOT do
- We do not sell or share your data, or your YouTube API Data, with third parties.
- We do not use YouTube API Data for advertising, or to serve or measure ads.
- We do not post, edit, delete, or moderate anything on YouTube without your explicit approval.
- We do not access videos or channels other than your own (for the connected-account features).
- Commento's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
- Commento uses the YouTube API Services. By using Commento you also agree to the YouTube Terms of Service; Google's handling of your data is described in the Google Privacy Policy.
Deleting your data
You can disconnect your channel in Settings (this deletes your stored tokens and channel link immediately), remove any scanned video, sign out to end your session, or revoke access in your Google account. To delete your account and all associated data, disconnect in Settings or email us and we will erase it.
Changes to this policy
If we change what we access, collect, store or use, we will update this page and the "last updated" date above.
Contact
siddhantjain2604@gmail.com · Commento home · Terms of Service