Privacy
What we process, and what we refuse to keep.
What the product does
CommentCraft is a Chrome extension that drafts LinkedIn comments. You approve every comment before it posts. Nothing posts automatically.
Post text
To write a draft we send the post text, plus the writing identity you saved (about-you, positions, tones, examples), to our API. The API forwards that to OpenRouter, who runs the model. Post bodies are never logged or stored — that rule is enforced in code, not just on this page. We do not train on your writing.
Licence and usage
A licence key identifies you. We store the key, its plan, status, and a credit ledger of what was reserved and settled (model class, pipeline, cost) — not the comment. Settings sync through your Chrome profile, not through our servers.
Processors
- OpenRouter — inference. Sub-processor of the model providers you actually hit.
- Hostinger — the VPS in the EU that runs the API and this site.
- Paddle — merchant of record for paid plans, once checkout is live. Not processing yet.
- Resend — transactional email (licence delivery), once signup is live. EU region. Not processing yet.
This website
The marketing site is static. We do not set analytics cookies. Server access logs on the reverse proxy record request metadata (IP, path, user-agent), not form bodies — there are no forms yet.
Legal bases (GDPR)
Art. 6(1)(b) for providing the draft you asked for. Art. 6(1)(c) for invoices and tax once Paddle is live (Paddle is the seller of record). Art. 6(1)(f) for securing the API against abuse.
Your rights
Access, rectification, erasure, restriction, portability, objection. Lodge a complaint with the LDI NRW or your local authority. Email hello@commentcraft.app.