Privacy
What we process, and what we refuse to keep.
What the product does
CommentCraft is a Chrome extension that drafts LinkedIn comments. You approve every comment before it posts. Nothing posts automatically.
Post text
To write a draft we send the post text, plus the writing identity you saved (about-you, positions, tones, examples), to our API. The API forwards that to OpenRouter, who runs the model. Post bodies are never logged or stored — that rule is enforced in code, not just on this page. We do not train on your writing.
Licence and usage
A licence key identifies you. We store the key, its plan, status, and a credit ledger of what was reserved and settled (model class, pipeline, cost) — not the comment. Settings sync through your Chrome profile, not through our servers.
Processors
- OpenRouter — inference. Sub-processor of the model providers you actually hit.
- Hostinger — the VPS in the EU that runs the API and this site.
- Paddle — merchant of record for paid plans. They take the card and hold the payment details; we never see them. They also collect your email and, if you tick the box at checkout, your consent to product emails.
- Resend — transactional email: your licence key, and a warning if a payment fails. EU region.
Email we send you
Two mails are part of the product and are not optional: your licence key when you sign up, and a warning if a payment fails. Without the first you have nothing to paste into the extension.
Product updates are separate and are opt-in only, through a checkbox at Paddle's checkout that is unticked by default. Every such mail carries an unsubscribe link, and you can withdraw consent at any time by replying or emailing us — it does not affect your licence.
This website
The marketing site is static. We do not set analytics cookies. Server access logs on the reverse proxy record request metadata (IP, path, user-agent), not form bodies.
Two pages talk to our API. /get loads Paddle's checkout script from cdn.paddle.com — Paddle sets its own cookies there, under their privacy policy. /manage sends the licence key or email address you type to our API in order to open Paddle's billing portal or re-send your key; neither is stored beyond the request.
Legal bases (GDPR)
Art. 6(1)(b) for providing the draft you asked for, for delivering your licence key, and for telling you a payment failed. Art. 6(1)(c) for invoices and tax (Paddle is the seller of record). Art. 6(1)(f) for securing the API against abuse. Art. 6(1)(a) — your consent — for product-update emails, and for nothing else.
Your rights
Access, rectification, erasure, restriction, portability, objection. Lodge a complaint with the LDI NRW or your local authority. Email hello@commentcraft.app.