Privacy Policy

Last updated: March 24, 2026

1. Introduction

Comment2Content ("we", "us", or "our") operates the Comment2Content platform, an AI-powered tool that helps YouTube creators turn their video comments into structured content ideas. This Privacy Policy explains what data we collect, how we use it, and your rights regarding that data.

By using Comment2Content you agree to the practices described in this policy. If you have questions, contact us at the address in the Contact section below.

2. Information We Collect

  • Account data — your email address and a hashed password. We never store passwords in plaintext.
  • Channel data — the YouTube channel name or URL you provide when connecting a channel. We do not request YouTube login credentials or OAuth access from you; we use our own server-side API key to fetch publicly available comment data.
  • Usage data — the number of video analyses and content ideas you generate each billing period. We use this solely to enforce your plan limits.
  • AI-generated outputs — analyses and content ideas generated by the service, stored in your account so you can access them later.
  • Billing data — your current plan type and billing period. All payment card details are handled exclusively by Stripe and never touch our servers.
  • Session data — an authentication token set in an HTTP-only cookie when you log in. See Section 4 for details.

3. How We Use Your Information

  • To provide the service — fetching public YouTube comment data, running AI analysis, and generating content ideas on your behalf.
  • To manage your subscription and enforce monthly plan limits.
  • To communicate with you about your account — billing confirmations, limit notifications, and material service changes.

We do not sell your data to third parties. We do not use your data for advertising purposes.

4. Cookies & Session Tokens

We use a single HTTP-only session cookie to keep you authenticated between page loads. This cookie contains a signed token and cannot be read by JavaScript. It is cleared when you log out.

We do not use third-party tracking cookies, analytics cookies, or advertising cookies.

5. Third-Party Services

  • YouTube Data API v3 (Google) — we use this API server-side with our own credentials to retrieve publicly available comments from the channel name you provide. Your personal Google account is not accessed.
  • OpenAI— comment data is sent to OpenAI's API to perform AI analysis and generate content ideas. OpenAI's data handling is governed by their privacy policy.
  • Stripe — all payment processing is handled by Stripe. We store only your plan type and billing period; no card data is stored on our servers.
  • Cloud database provider — your account data and AI-generated outputs are stored with a cloud PostgreSQL provider. We will name this provider in an update to this policy prior to public launch.

6. Data Retention

We retain your account data for as long as your account is active. If you delete your account, your data will be permanently removed within 30 days. You can request account deletion at any time by contacting us.

7. Your Rights

You have the right to access, correct, or delete the personal data we hold about you. To exercise any of these rights, contact us at the email address below. We will respond within 30 days.

If you are located in the European Economic Area, you may also have the right to data portability and the right to object to certain processing activities.

8. Security

All passwords are hashed before storage. All data in transit is encrypted via HTTPS. Session cookies are HTTP-only and scoped to our domain. We do not store any plaintext credentials.

While we take reasonable precautions, no system is completely secure. If you discover a security issue, please contact us immediately.

9. Contact

For privacy-related questions or requests, contact us at: privacy@comment2content.com