Data handling & compliance overview

Last updated: 28 Apr 2026 · Informational summary only (not legal advice).

What data we collect

CommentPilot is designed to process only the data needed to help you review and answer community comments.

  • Comment and thread data: comment text, author handle/channel name, timestamps, and moderation state.
  • Workspace settings: tone preferences, guardrails, moderation rules, connected account settings, and workflow options.
  • Assets you add: optional brand examples, style notes, canned responses, and linked media metadata.
  • Optional context data: transcript snippets, title/description, and other context that you explicitly enable for better draft quality.

What data is used for AI generation (and why)

When you request AI suggestions, we send only relevant context to generate a draft response that matches your configured style and safety rules.

  • Typical inputs include the comment text, nearby thread context, and your selected brand voice instructions.
  • Optional context (like transcript snippets) is used only when you enable it, to improve relevance and reduce hallucinated replies.
  • Outputs are shown as drafts for human review before publishing.

Retention and deletion principles

  • We aim for data minimization: keep what is operationally necessary, for as short a period as practical.
  • Operational logs and generated drafts are retained to support quality, abuse prevention, and troubleshooting.
  • When data is deleted in product workflows, we propagate deletion to active systems and scheduled backups under normal retention windows.
  • If legal obligations require preservation (for example, fraud/security investigations), retention may be extended for that limited purpose.

User controls

  • Edit: adjust tone, rules, and draft content at any time before publishing.
  • Delete: remove stored assets/context where controls are available in the app.
  • Export: workspace export/report features may be available depending on your plan and integration scope.
  • Disable context features: optional transcript or media-context support can be turned off if not needed.

Third-party processing (LLM/API providers)

CommentPilot may use external AI and infrastructure providers to process generation requests. Those providers may temporarily process submitted content to deliver the requested output and maintain service reliability/security.

  • We share only the request data needed for the generation task.
  • Provider-side handling is subject to their contracts and privacy/security terms.
  • Where available, we prefer enterprise/privacy-preserving controls and avoid unnecessary payloads.

Safety and policy posture

  • Draft-first workflow: AI suggestions are produced as drafts for human approval.
  • Anti-spam safeguards: policy filters and queue controls reduce low-quality or risky responses.
  • Human accountability: final publishing decisions remain with your team.

How thumbnail/video context material is handled

Thumbnail, title, and video-context support is designed as an opt-in enhancement for better relevance. By default, only core comment context is required.

  • When enabled, we may process lightweight metadata and selected context snippets to improve response quality.
  • We do not use extra media context unless your workspace feature settings permit it.
  • Keep enabled context proportional to your use case; if uncertain, prefer minimal context.

This page is a product-level summary for transparency and operations. It does not replace your legal agreements, privacy notice, or terms.