Privacy Policy
Last Updated: July 2026
This Privacy Policy explains how CommentShark collects, uses, and protects your information when you use our website, free tools, and service. By using CommentShark, you agree to the collection and use of information as described in this policy.
Revoking Access
You can revoke CommentShark's access to your data at any time via Google's security settings:
YouTube Data API and Google User Data
CommentShark uses YouTube API Services as an API client and follows the YouTube API Services Terms of Service. By using CommentShark, you agree to be bound by the YouTube API Services Terms of Service and Google's Privacy Policy.
CommentShark's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Information We Collect
CommentShark collects the information necessary to provide the service:
- Login Information: Your email address and name from Google OAuth authentication.
- YouTube Channel Data: Basic channel information, video details, and comments (as authorized by you).
- Content You Create: Automation rules, channel context, reply text, and support or feedback messages you send us.
- Marketing Attribution: If you arrive from a marketing link or ad, the campaign parameters and ad click identifiers in the URL (see "Cookies, Analytics, and Advertising" below).
- Payment Information: If you subscribe to a paid plan, payment processing is handled by Stripe. CommentShark does not store your credit card or payment details.
We do not collect or store any sensitive information such as passwords. All authentication is handled securely through Google OAuth.
How We Use Your Information
CommentShark uses the information collected from your YouTube account, including YouTube API Services data, solely to provide and improve the service you have signed up for. Specifically, your information is used to:
- Authenticate you and maintain your account session via Google OAuth.
- Read your channel metadata, video metadata, and comments so we can display them in your dashboard and analytics views.
- Match incoming comments against the moderation and auto-reply rules you have configured, and, only when a rule fires, post replies, moderate, or remove comments on your behalf via the YouTube Data API.
- Power the AI features included in your plan, such as classifying comments against your rules, generating reply drafts, scoring comment sentiment, and suggesting rules (see "How We Process Your Information" below for how this works).
- Provide aggregate analytics (sentiment, engagement, top commenters) about your own channel back to you.
- Send transactional emails and, where you have enabled them, push notification mirrors of those emails (sign-in confirmations, billing receipts, security alerts), plus periodic activity-report emails if you have opted in, and occasional product updates and tips, which you can unsubscribe from at any time.
- Process payments and manage subscription entitlements for paid tiers.
- Verify your identity, confirm that the service was delivered, and investigate or resolve billing disputes and chargebacks (including, where a payment is disputed, providing records of your account authentication, activity, and service delivery to your bank or card network).
- Maintain service reliability, detect abuse, debug errors, and comply with legal obligations.
We do not use YouTube API Services data, or any data derived from it, to train generalized AI/ML models, to build advertising profiles, or for any purpose other than providing the CommentShark service to you. We do not sell your data.
How We Process Your Information
Your information is processed on cloud infrastructure operated by Amazon Web Services (AWS) in the United States. Processing includes:
- Storing OAuth refresh tokens (encrypted at rest) so the service can call the YouTube Data API on your behalf for the features you have enabled.
- Storing a rolling window of your synced YouTube comments and channel metadata (maximum 30 days; see "Data Retention" below) in a managed database, used as a working set for matching, analytics, and the dashboard.
- Sending comment text and related context to our third-party AI providers (listed below) to power AI features. Some of this processing runs automatically and continuously as your comments sync: for example, classifying new comments against the rules you have enabled, and, on paid plans, scoring comment sentiment. Other AI processing runs when you use a specific feature, such as generating a reply draft or a channel profile.
- Generating short-lived embeddings of comments and transcripts to power semantic search and matching features.
- Logging request and event metadata (no comment bodies in long-term log storage beyond what is necessary to debug a specific failure) for monitoring and abuse prevention.
All data is transmitted over TLS in transit and encrypted at rest. Access to production systems is restricted to authorized CommentShark personnel and is audit-logged.
Data About People Without a CommentShark Account
Commenters on our users' channels: To provide the service, we process public YouTube comments posted on our users' videos, including the comment text and the commenter's public display name and channel ID, obtained through the YouTube Data API. This data is used only to provide comment-management features to the channel owner, is processed by the AI providers listed below for those features, and is automatically deleted from our systems within 30 days. If you are a commenter and want your data removed from our systems sooner, contact us at support@commentshark.com. The comment itself lives on YouTube and is governed by YouTube's own terms and privacy policy.
Free tool visitors: Our free tools fetch publicly available YouTube data on your request, without an account. We process your IP address to enforce fair-use rate limits, and we may cache a generated result briefly (up to 30 minutes) so a refresh does not re-fetch it. We do not build profiles of free-tool visitors.
Business outreach: If we contact you about CommentShark, we obtained your publicly listed business contact information, for example an email address you published on your channel or website. Reply to any such message and we will not contact you again.
How We Share Your Information
CommentShark does not sell, rent, or trade your personal information or YouTube API Services data. We share information only as described below.
Internal parties
Within CommentShark, access to user data is limited to the authorized engineering, support, and operations personnel who need it to operate the service, respond to support requests, or investigate abuse or security incidents. All personnel are bound by confidentiality obligations. We do not share user data with internal teams for marketing, advertising, or model-training purposes.
External parties (sub-processors)
We rely on the following third-party service providers ("sub-processors") to operate CommentShark. Each receives only the minimum data necessary to perform its function, and each is contractually required to protect that data:
- Google LLC (YouTube Data API, Google OAuth): Authentication, channel/video/comment reads, and writes (posting replies, moderating comments) you authorize. Governed by Google's Privacy Policy.
- Google LLC (Gemini API): AI inference for the AI features described above. Data submitted via the paid Gemini API is not used to train Google's models.
- Google LLC (Analytics, Tag Manager, Ads): Website and app usage analytics and advertising conversion measurement, as described in "Cookies, Analytics, and Advertising" below. YouTube API Services data is never sent to these tools.
- Amazon Web Services, Inc. (AWS): Hosting, compute (Lambda), database, object storage (S3), email delivery (SES), and supporting infrastructure in the United States.
- Stripe, Inc.: Payment processing for paid subscriptions. CommentShark never sees or stores your full card number; Stripe handles payment data under its own privacy policy.
- Mailgun Technologies, Inc.: Inbound email processing for our support and contact addresses.
- Browser push services (Apple, Google, Mozilla): Deliver the push notifications you opt in to, via your browser vendor's push infrastructure.
We will update this list when sub-processors change. We do not transfer YouTube API Services data to any third party for the purpose of advertising, model training, profiling, or any use beyond providing CommentShark functionality to you.
Legal and safety
We may disclose information when we have a good-faith belief that doing so is required by law, valid legal process (e.g. a subpoena or court order), or necessary to protect the rights, safety, or property of CommentShark, our users, or the public, for example to prevent fraud, abuse, or security incidents. Where legally permitted, we will notify the affected user before disclosure.
Business transfers
If CommentShark is involved in a merger, acquisition, financing due-diligence, reorganization, bankruptcy, or sale of assets, user information may be transferred as part of that transaction. We will notify you (via email and/or a prominent notice on this page) of any such change in ownership or use of your information.
Cookies, Analytics, and Advertising
Essential cookies: When you sign in, we store a signed session token in a secure, HttpOnly cookie so you stay logged in. Google's OAuth service may also set its own cookies during the login process. These are required for the service to work.
Analytics and ads measurement: Our public website and app use Google Analytics, Google Tag Manager, and Google Ads conversion measurement. These tools set cookies (such as _ga) and process your IP address and page interactions so we can understand how visitors find and use CommentShark and measure our advertising. For signed-in users we send Google Analytics a one-way hashed identifier; we never send your email address, name, or channel name to analytics tools, and YouTube API Services data is never shared with them. If you are visiting from the EEA or the UK, these tools stay off until you allow them through our cookie consent banner.
Marketing attribution: If you arrive from a marketing link or ad, we store the campaign parameters and ad click identifiers (such as gclid or fbclid) from the URL in your browser for up to 90 days. If you later sign up, we associate them with your account so we know which marketing works. We use this internally only and never sell it.
Your choices: You can block or delete cookies in your browser settings, and you can opt out of Google Analytics with Google's opt-out browser add-on. You can change your analytics choice at any time via the "Cookie preferences" link in the site footer. Blocking analytics cookies does not affect the service.
Log Data
When you use CommentShark, we may collect standard log data through our hosting infrastructure. This may include:
- IP address
- Approximate location and timezone derived from your IP address at sign-in (used to localize your reports and schedules)
- Browser type and version
- Device type and operating system
- Pages visited and time spent
- Error logs for debugging purposes
This data is used solely for maintaining service quality, debugging issues, and improving the user experience.
Data Storage and Security
Your data is stored securely using industry-standard practices with encryption in transit and at rest. While we strive to use commercially acceptable means of protecting your information, please be aware that no method of electronic transmission or storage is 100% secure. If we become aware of a security breach affecting your personal information, we will notify you as required by applicable law.
Data Retention
We keep different classes of data for different lengths of time:
- Synced YouTube comments and channel metadata: A rolling maximum of 30 days, then automatically purged.
- Automation records (which rule fired and what action was taken): Kept while your account is active so your automations never act on the same comment twice; the comment text and commenter details are scrubbed from these records after 30 days.
- Aggregate daily channel statistics (counts only, never comment text or commenter identities): Kept while your account is active to power long-range analytics.
- Records of emails we send you: Delivery records are kept for audit purposes; the message body is purged after 90 days.
- Operational and security logs: Up to 2 years, for debugging, abuse prevention, and audit.
- Encrypted backups: Rotate automatically and are deleted within 60 days.
If you delete your CommentShark account (from the Profile page in your dashboard), your synced YouTube data, rules, and account records are deleted immediately, your OAuth refresh token is revoked, and any active subscription is cancelled. Residual copies in encrypted backups age out within 60 days. You can also revoke CommentShark's access to your YouTube data at any time through Google security settings, which immediately prevents further synchronization.
Your Rights and Choices
You are in control of your data, wherever you live:
- Access and portability: Your dashboard shows the data we hold about your channel, and you can export your comment data at any time.
- Deletion: Delete your account from the Profile page in your dashboard, or email us and we will do it for you.
- Correction: Most account data comes directly from your Google account and can be corrected there; for anything else, contact us.
- Email: Every marketing, tips, or activity-report email includes an unsubscribe link, and you can manage email preferences on your Profile page. Transactional emails (receipts, security alerts) are sent as needed to operate your account.
- Push notifications: Revoke at any time in your browser or device notification settings.
- Google access: Revoke CommentShark's access at any time from Google's security settings (link above).
Depending on where you live, these rights may also be guaranteed by law (for example the GDPR in the EEA and UK, or the CCPA in California). We honor access, correction, deletion, and portability requests from all users regardless of location. To exercise any right, email support@commentshark.com from the address associated with your account; we verify requests via your Google sign-in. EEA and UK users may also lodge a complaint with their local supervisory authority.
International Users
CommentShark is operated from the United States and your information is processed on servers in the United States. If you use the service from outside the US, you understand that your information will be transferred to and processed in the US, where data protection laws may differ from those in your country.
Children's Privacy
CommentShark is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, contact us and we will delete it.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify users of material changes by email and by posting the updated policy on this page with a new "Last Updated" date. Your continued use of CommentShark after any changes constitutes acceptance of the updated policy.
Contact Us
If you have any questions or concerns about this Privacy Policy, please contact us at support@commentshark.com