Privacy Policy
Last Updated: August 2026
This Privacy Policy explains how CommentShark collects, uses, and protects your information when you use our website, free tools, and service. By using CommentShark, you agree to the collection and use of information as described in this policy.
Revoking Access
You can revoke CommentShark's access to your data at any time via Google's security settings:
YouTube Data API and Google User Data
CommentShark uses YouTube API Services as an API client and follows the YouTube API Services Terms of Service. By using CommentShark, you agree to be bound by the YouTube API Services Terms of Service and Google's Privacy Policy.
CommentShark's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Information We Collect
CommentShark collects the information necessary to provide the service:
- Login Information: Your email address and name from Google OAuth authentication.
- YouTube Channel Data: Basic channel information, video details, and comments (as authorized by you).
- Content You Create: Automation rules, channel context, reply text, and support or feedback messages you send us.
- Marketing Attribution: If you arrive from a marketing link or ad, the campaign parameters and ad click identifiers in the URL (see "Cookies, Analytics, and Advertising" below).
- Customer Referral Information: If you use a customer referral link, we record the referral slug, click and qualification times, reward status, and any qualifying subscription payment or later refund or dispute needed to administer the program.
- Payment Information: If you subscribe to a paid plan, payment processing is handled by Stripe. CommentShark does not store your credit card or payment details.
We do not collect or store any sensitive information such as passwords. All authentication is handled securely through Google OAuth.
How We Use Your Information
CommentShark uses the information collected from your YouTube account, including YouTube API Services data, solely to provide and improve the service you have signed up for. Specifically, your information is used to:
- Authenticate you and maintain your account session via Google OAuth.
- Read your channel metadata, video metadata, and comments so we can display them in your dashboard and analytics views.
- Match incoming comments against the moderation and auto-reply rules you have configured, and, only when a rule fires, post replies, moderate, or remove comments on your behalf via the YouTube Data API.
- Power the AI features included in your plan, such as classifying comments against your rules, generating reply drafts, scoring comment sentiment, and suggesting rules (see "How We Process Your Information" below for how this works).
- Provide aggregate analytics (sentiment, engagement, top commenters) about your own channel back to you.
- Send transactional emails and, where you have enabled them, push notification mirrors of those emails (sign-in confirmations, billing receipts, security alerts), plus periodic activity-report emails if you have opted in, and occasional product updates and tips, which you can unsubscribe from at any time.
- Process payments and manage subscription entitlements for paid tiers.
- Attribute customer referrals, issue and reverse referral rewards, enforce one-time eligibility and unpaid-referral limits, and investigate referral abuse.
- Verify your identity, confirm that the service was delivered, and investigate or resolve billing disputes and chargebacks (including, where a payment is disputed, providing records of your account authentication, activity, and service delivery to your bank or card network).
- Maintain service reliability, detect abuse, debug errors, and comply with legal obligations.
We do not use YouTube API Services data, or any data derived from it, to train generalized AI/ML models, to build advertising profiles, or for any purpose other than providing the CommentShark service to you. We do not sell your data.
How We Process Your Information
Your information is processed on cloud infrastructure operated by Amazon Web Services (AWS) in the United States. Processing includes:
- Storing OAuth refresh tokens (encrypted at rest) so the service can call the YouTube Data API on your behalf for the features you have enabled.
- Storing a rolling window of your synced YouTube comments and channel metadata (maximum 30 days; see "Data Retention" below) in a managed database, used as a working set for matching, analytics, and the dashboard.
- Sending comment text and related context to our third-party AI providers (listed below) to power AI features. Some of this processing runs automatically and continuously as your comments sync: for example, classifying new comments against the rules you have enabled, and, on paid plans, scoring comment sentiment. Other AI processing runs when you use a specific feature, such as generating a reply draft or a channel profile.
- Generating short-lived embeddings of comments and transcripts to power semantic search and matching features.
- Logging request and event metadata (no comment bodies in long-term log storage beyond what is necessary to debug a specific failure) for monitoring and abuse prevention.
All data is transmitted over TLS in transit and encrypted at rest. Access to production systems is restricted to authorized CommentShark personnel and is audit-logged.
Data About People Without a CommentShark Account
Commenters on our users' channels: To provide the service, we process public YouTube comments posted on our users' videos, including the comment text and the commenter's public display name and channel ID, obtained through the YouTube Data API. This data is used only to provide comment-management features to the channel owner, is processed by the AI providers listed below for those features, and is automatically deleted from our systems within 30 days. If you are a commenter and want your data removed from our systems sooner, contact us at [email protected]. The comment itself lives on YouTube and is governed by YouTube's own terms and privacy policy.
Free tool visitors: Our free tools fetch publicly available YouTube data on your request, without an account. We process your IP address to enforce fair-use rate limits, and we may cache a generated result briefly (up to 30 minutes) so a refresh does not re-fetch it. We do not build profiles of free-tool visitors.
Business outreach: If we contact you about CommentShark, we obtained your publicly listed business contact information, for example an email address you published on your channel or website. Reply to any such message and we will not contact you again.
How We Share Your Information
CommentShark does not sell, rent, or trade your personal information or YouTube API Services data. We share information only as described below.
Internal parties
Within CommentShark, access to user data is limited to the authorized engineering, support, and operations personnel who need it to operate the service, respond to support requests, or investigate abuse or security incidents. All personnel are bound by confidentiality obligations. We do not share user data with internal teams for marketing, advertising, or model-training purposes.
External parties (sub-processors)
We rely on the following third-party service providers ("sub-processors") to operate CommentShark. Each receives only the minimum data necessary to perform its function, and each is contractually required to protect that data:
- Google LLC (YouTube Data API, Google OAuth): Authentication, channel/video/comment reads, and writes (posting replies, moderating comments) you authorize. Governed by Google's Privacy Policy.
- Google LLC (Gemini API): AI inference for the AI features described above. Data submitted via the paid Gemini API is not used to train Google's models.
- Google LLC (Analytics, Tag Manager, Ads): Website and app usage analytics and advertising conversion measurement, as described in "Cookies, Analytics, and Advertising" below. YouTube API Services data is never sent to these tools.
- Amazon Web Services, Inc. (AWS): Hosting, compute (Lambda), database, object storage (S3), email delivery (SES), and supporting infrastructure in the United States.
- Stripe, Inc.: Payment processing for paid subscriptions. CommentShark never sees or stores your full card number; Stripe handles payment data under its own privacy policy.
- Mailgun Technologies, Inc.: Inbound email processing for our support and contact addresses.
- Browser push services (Apple, Google, Mozilla): Deliver the push notifications you opt in to, via your browser vendor's push infrastructure.
We will update this list when sub-processors change. We do not transfer YouTube API Services data to any third party for the purpose of advertising, model training, profiling, or any use beyond providing CommentShark functionality to you.
Legal and safety
We may disclose information when we have a good-faith belief that doing so is required by law, valid legal process (e.g. a subpoena or court order), or necessary to protect the rights, safety, or property of CommentShark, our users, or the public, for example to prevent fraud, abuse, or security incidents. Where legally permitted, we will notify the affected user before disclosure.
Business transfers
If CommentShark is involved in a merger, acquisition, financing due-diligence, reorganization, bankruptcy, or sale of assets, user information may be transferred as part of that transaction. We will notify you (via email and/or a prominent notice on this page) of any such change in ownership or use of your information.
Cookies, Analytics, and Advertising
CommentShark centralizes the transport settings for the first-party cookies it owns, while keeping sign-in, consent, marketing attribution, and customer-referral rules separate. Our current first-party cookies are:
__Host-commentshark-login-token— an essential, secure, HttpOnly cookie used only to complete the Google OAuth sign-in handoff. It lasts no more than 5 minutes and is cleared when exchanged. The signed application session returned by that exchange is stored in your browser's local storage, not in an HttpOnly cookie, and expires after 30 days.__Host-commentshark-consent— an essential, client-readable preference cookie that stores only whether you granted or denied analytics and marketing storage. It lasts 365 days and mirrors the same choice in local storage so both the server and browser can honor it. It is not an advertising identifier.cs_attribution— a marketing cookie used to carry consented first-touch campaign information through sign-in. It lasts up to 90 days and is mirrored in local storage before signup.__Host-commentshark-referral— a functional, secure, HttpOnly cookie created when you deliberately follow a CommentShark customer-referral link. It lasts up to 90 days and is used only to credit that requested referral.
Google's OAuth service may set its own cookies while you sign in. Browser storage used for theme, drafts, and other settings is functional product storage rather than advertising tracking.
Analytics and ads measurement: Our public website and app use Google Analytics, Google Tag Manager, and Google Ads conversion measurement. These tools set cookies (such as _ga) and process your IP address and page interactions so we can understand how visitors find and use CommentShark and measure our advertising. For signed-in users we send Google Analytics a one-way hashed identifier; we never send your email address, name, or channel name to analytics tools, and YouTube API Services data is never shared with them. If you are visiting from the EEA or the UK, these tools stay off until you allow them through our cookie consent banner.
Marketing attribution: When your current cookie preference allows it, a marketing link or ad may place campaign parameters and ad click identifiers (such as gclid or fbclid) in the marketing cookie and local storage described above. If you later sign up, we associate that first-party information with your account so we know which marketing works. The browser copy is deleted after a successful handoff to the server, and choosing "Essential only" deletes any remaining browser marketing attribution and prevents it from being sent. We use this internally only and never sell it.
Customer referrals: Referral attribution is separate from marketing attribution. Following a cmnt.sh/r/... link explicitly asks CommentShark to remember who referred you so both creators can receive the advertised benefit. The signed referral cookie is first-party only, is not used for cross-site or advertising tracking, and does not enable Google Analytics. A newer valid referral link replaces it. We clear it once signup attribution is successfully claimed or reaches a final non-qualifying result; a temporary technical failure may leave it available for retry until it expires.
Your choices: You can block or delete cookies in your browser settings, and you can opt out of Google Analytics with Google's opt-out browser add-on. You can change your analytics and marketing-storage choice at any time via the "Cookie preferences" link in the site footer. Choosing essential storage only does not affect the service or turn off a functional referral you explicitly requested.
Log Data
When you use CommentShark, we may collect standard log data through our hosting infrastructure. This may include:
- IP address
- Approximate location and timezone derived from your IP address at sign-in (used to localize your reports and schedules)
- Browser type and version
- Device type and operating system
- Pages visited and time spent
- Error logs for debugging purposes
This data is used solely for maintaining service quality, debugging issues, and improving the user experience.
Data Storage and Security
Your data is stored securely using industry-standard practices with encryption in transit and at rest. While we strive to use commercially acceptable means of protecting your information, please be aware that no method of electronic transmission or storage is 100% secure. If we become aware of a security breach affecting your personal information, we will notify you as required by applicable law.
Data Retention
We keep different classes of data for different lengths of time:
- Synced YouTube comments and channel metadata: A rolling maximum of 30 days, then automatically purged.
- Automation records (which rule fired and what action was taken): Kept while your account is active so your automations never act on the same comment twice; the comment text and commenter details are scrubbed from these records after 30 days.
- Aggregate daily channel statistics (counts only, never comment text or commenter identities): Kept while your account is active to power long-range analytics.
- Records of emails we send you: Delivery records are kept for audit purposes; the message body is purged after 90 days.
- Operational and security logs: Up to 2 years, for debugging, abuse prevention, and audit.
- Customer-referral and reward records: We retain the stable public referral-slug reservation, commercial reward and payment/reversal audit facts, and pseudonymous channel fingerprints needed to enforce one-time rewards, the unpaid-referral limit, refunds, disputes, and abuse prevention. These records are retained for the life of the referral program and afterward as reasonably necessary for audit, fraud prevention, and legal claims.
- Encrypted backups: Rotate automatically and are deleted within 60 days.
If you delete your CommentShark account (from the Profile page in your dashboard), your live account, synced YouTube data, rules, spendable referral actions, and other ordinary account records are deleted immediately, your OAuth refresh token is revoked, and any active subscription is cancelled. The limited referral records described above remain with live user references removed. Before deleting the raw channel ID, we retain a domain-separated SHA-256 channel fingerprint in a referral anti-abuse tombstone. The fingerprint is pseudonymous, not anonymous: it lets us recognize the same public channel ID if it registers again, but the tombstone does not contain the raw channel ID and cannot restore the deleted account or its rewards. Residual copies of deleted data in encrypted backups age out within 60 days. You can also revoke CommentShark's access to your YouTube data at any time through Google security settings, which immediately prevents further synchronization.
Your Rights and Choices
You are in control of your data, wherever you live:
- Access and portability: Your dashboard shows the data we hold about your channel, and you can export your comment data at any time.
- Deletion: Delete your account from the Profile page in your dashboard, or email us and we will do it for you.
- Correction: Most account data comes directly from your Google account and can be corrected there; for anything else, contact us.
- Email: Every marketing, tips, or activity-report email includes an unsubscribe link, and you can manage email preferences on your Profile page. Transactional emails (receipts, security alerts) are sent as needed to operate your account.
- Push notifications: Revoke at any time in your browser or device notification settings.
- Google access: Revoke CommentShark's access at any time from Google's security settings (link above).
Depending on where you live, these rights may also be guaranteed by law (for example the GDPR in the EEA and UK, or the CCPA in California). We honor access, correction, deletion, and portability requests from all users regardless of location. To exercise any right, email [email protected] from the address associated with your account; we verify requests via your Google sign-in. EEA and UK users may also lodge a complaint with their local supervisory authority.
International Users
CommentShark is operated from the United States and your information is processed on servers in the United States. If you use the service from outside the US, you understand that your information will be transferred to and processed in the US, where data protection laws may differ from those in your country.
Children's Privacy
CommentShark is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, contact us and we will delete it.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify users of material changes by email and by posting the updated policy on this page with a new "Last Updated" date. Your continued use of CommentShark after any changes constitutes acceptance of the updated policy.
Contact Us
If you have any questions or concerns about this Privacy Policy, please contact us at [email protected]