Privacy Policy
Effective Date: [DATE]
Last Updated: [DATE]
Draft: highlighted items in brackets are placeholders to complete before publishing. This draft should be reviewed by a qualified lawyer or privacy professional.
1. Introduction
SafeCommet ("SafeCommet", "we", "us", "our") is operated by KANBS. SafeCommet helps people manage and moderate comments on their Instagram Professional accounts. This Privacy Policy explains what information we handle, why, who we share it with, and the choices you have.
SafeCommet is an independent third-party service. See the Meta/Instagram disclaimer.
2. Scope
This policy applies to SafeCommet's website at [WEBSITE URL], its web application, and related services (together, the "Service"). It applies to:
- Account holders: people who sign up for SafeCommet and connect an Instagram Professional account.
- Commenters and other Instagram users: people whose comments or interactions are processed because an account holder has enabled SafeCommet on their account.
It does not cover Meta, Instagram, Razorpay, or other third-party services, which have their own policies.
3. Information we collect
We do not necessarily collect every category below from every person. What we handle depends on how you use the Service and which features you enable.
| Category | Examples | Why we handle it |
|---|---|---|
| Instagram account information | Instagram username, account ID, profile information made available through the API | To connect and identify your account and show it in your dashboard |
| Instagram comment information | Comment text, comment ID, commenter's Instagram username and ID (where the API provides them), post/media ID | To provide moderation, comment management, and automated replies |
| Moderation information | Moderation result, classification/category, moderation decision, your moderation rules and settings | To apply your rules, record what action was taken, and let you review it |
| Authentication information | OAuth access tokens; refresh tokens, if applicable | To keep your Instagram connection working and act on your behalf |
| Automation information | Auto-reply rules, trigger keywords/messages, response content you configure, references to PDFs or other content set up for delivery | To run the automations you configure |
| Technical information | Logs, error logs, security logs, technical metadata needed to run and troubleshoot the Service | To operate, secure, and debug the Service |
| Commercial/account information | Usage information, billing records, subscription and payment-related information | To manage your plan, process payments, and support you |
4. How we collect information
- Directly from you: when you register, configure moderation rules and automations, contact us, or manage your subscription.
- Through Meta/Instagram: when you connect your account through Meta/Instagram OAuth, we receive information and credentials made available under the permissions you grant. Through the applicable Instagram/Meta APIs, we receive comments and interactions associated with your connected account.
- Through your use of SafeCommet: your settings, configurations, and activity in the Service.
- From payment providers: such as Razorpay, which may give us limited payment and subscription information.
- Automatically: through technical logs and the normal operation of the Service.
Information you give us directly is under your control. Information received through Meta/Instagram depends on the permissions you grant and what the APIs make available.
5. How we use information
| Purpose | Data typically involved |
|---|---|
| Authenticate you and connect your Instagram account | Account, authentication information |
| Detect abusive, vulgar, offensive, or unwanted comments | Comment information |
| Apply your moderation rules and hide/remove comments where you have authorized it | Comment, moderation information |
| Generate automated replies and run keyword-triggered automations | Comment, automation information |
| Deliver content or PDFs you have configured | Automation information |
| Maintain your settings and show dashboards, logs, and usage | Moderation, automation, technical, usage information |
| Process subscriptions and payments | Commercial/account information |
| Detect fraud, abuse, and security incidents | Technical, account, authentication information |
| Debug errors and maintain and improve the Service | Technical information, usage information |
| Comply with legal obligations | Any, as required |
We do not use your information, or commenter information, for advertising, and we do not sell it to advertisers or anyone else.
6. Instagram/Meta integration
- You connect your Instagram Professional account voluntarily through Meta/Instagram OAuth.
- SafeCommet accesses information and performs actions only as permitted by the authorization you grant and by the applicable Meta/Instagram APIs.
- We use that access for comment moderation, comment management, automated replies, keyword-triggered automation, delivery of configured content, account connection, security and troubleshooting, and service usage analytics where applicable.
- You can disconnect your Instagram account at any time (see Data deletion and OAuth and account connections).
- Meta/Instagram processes information on its own platforms under its own terms and privacy policies. We do not control that processing.
- We do not claim ownership of your Instagram content or of comments posted on your account. That content remains yours or its authors'.
7. Commenter information
When you enable comment-management features, SafeCommet may process information tied to comments on your account, including:
- Comment text and comment ID
- The commenter's Instagram username and Instagram ID, where the API provides it
- The related post/media ID
- The moderation classification/result
We process this to give you, the connected account owner, the moderation and automation functionality you requested. We do not sell commenter information, and we do not use it to build advertising profiles.
If you are a commenter and want to ask about information relating to you, contact us at [PRIVACY EMAIL]. We may need to coordinate with the account owner whose account the comment relates to.
8. Automated moderation and AI
SafeCommet uses automated and AI-based processing to analyze comments for potentially abusive, vulgar, offensive, or unwanted content.
- Comment content may be processed by automated moderation systems.
- The system may classify or score comments, and the result may be used to decide whether an action such as hiding or removing a comment is taken.
- Automated moderation can make mistakes. It may hide comments that are acceptable or miss comments that are not. We do not represent its output as perfectly accurate.
- You are responsible for configuring moderation rules that suit your account and for reviewing your automation settings and moderation logs.
SafeCommet may use third-party AI or machine-learning service providers to process content for moderation and automation purposes. The specific providers used may change over time and will be identified or otherwise disclosed where required by applicable law.
[AI USE STATEMENT: confirm whether comment data is or is not used to train any models, by us or by providers.]
9. Automated replies and content delivery
If you enable these features:
- SafeCommet may post automated replies to comments according to rules you configure.
- SafeCommet may respond to a configured keyword or message with an automated response, which may include delivering a PDF or other content you have set up.
- The rules, trigger keywords, response content, and content references are provided and controlled by you. You are responsible for the content you configure and for having the right to share it.
- To operate these features, we process the triggering comment or message, the sender's identifying information as provided by the API, and the related automation records.
10. Data sharing
We do not sell personal information to third parties. We may share information in these situations:
- Meta/Instagram, as necessary to provide the integration (for example, sending a request to hide a comment or post a reply).
- Infrastructure and service providers that host, store, log, monitor, or help us operate the Service.
- AI or machine-learning providers, where used, to process content for moderation and automation.
- Payment providers, such as Razorpay, to process payments.
- Professional advisers, such as lawyers and accountants, where necessary.
- Government authorities or law-enforcement agencies, where required by law or a valid legal process.
- Successors, in a merger, acquisition, restructuring, or sale of assets, subject to applicable law.
11. Third-party services
SafeCommet may integrate with or rely on:
- Meta / Instagram. Privacy policy: [META PRIVACY POLICY LINK]
- Razorpay. Privacy policy: [RAZORPAY PRIVACY POLICY LINK]
- AI/ML providers: [AI PROVIDER NAME AND PRIVACY LINK, once finalized]
- Hosting, database, and infrastructure providers: [PROVIDER NAMES AND LINKS, once finalized]
- Other services necessary to operate the Service
Third-party services have their own terms and privacy policies, and we are not responsible for their practices.
12. Razorpay and payments
We may use Razorpay to process payments.
- Payment information you enter is processed by Razorpay.
- We may receive limited payment and subscription information needed to manage your account, such as plan, payment status, and transaction references.
- Sensitive payment credentials are intended to be handled by the payment provider rather than stored directly by SafeCommet, where applicable.
- We may keep billing and subscription records.
- Razorpay's own terms and privacy policy may also apply.
13. Data retention
- You control some retention. Where the Service provides retention or deletion settings, you can use them to control certain data.
- We keep information as long as needed to provide the Service.
- Automatic deletion after six months. Where applicable, inactive or retained data may be automatically deleted after six months, according to the Service's retention mechanisms. [RETENTION DETAIL: state which data this covers and when the six months start.]
- Some information may be kept longer where necessary for security, fraud prevention, legal obligations, dispute resolution, accounting, or legitimate operational purposes.
- Exact retention periods may vary by the type of information and your configuration. We do not guarantee that every category of data is deleted at exactly six months.
14. Data deletion
You can disconnect Instagram, delete your account, or ask us to delete your data. Some information may be kept where the law requires or where it is reasonably needed (see below).
Disconnect Instagram
- Sign in to SafeCommet at [WEBSITE URL].
- Go to [DISCONNECT LOCATION IN APP, e.g. Settings, then Connected accounts].
- Choose Disconnect next to your Instagram account.
You can also remove SafeCommet's access from your Instagram/Meta account settings. Disconnecting stops SafeCommet from reading or acting on your comments. [CONFIRM what is deleted at disconnect, such as tokens, and what remains until deletion.]
Delete your SafeCommet account
[CONFIRM whether in-app account deletion exists at launch. If yes, describe the steps. If not, use "Ask us to delete your data" below.]
Ask us to delete your data
Send your request using [DATA DELETION REQUEST METHOD], or email [PRIVACY EMAIL]. Include:
- The email address on your SafeCommet account, or your Instagram username
- What you want deleted (your account and data, or specific information)
- If you are a commenter rather than an account holder: your Instagram username and, if you can, the post or comment concerned
We may need to verify your identity before acting on a request. We aim to respond within [RESPONSE TIMEFRAME].
What gets deleted
- Your account and settings, including moderation rules and automation configuration
- Instagram-related data we stored for you, such as comment records and moderation results
- Stored OAuth tokens
[CONFIRM this list against what the system actually deletes.]
What we may keep
We may retain some information where legally required or reasonably necessary for security, fraud prevention, accounting, dispute resolution, or legal purposes. This can include billing and subscription records and security logs.
Automatic deletion
See Data retention. Automatic deletion does not guarantee that every category of data is deleted at exactly six months.
15. Security
We aim to use reasonable technical and organizational safeguards, which may include:
- Access controls and authentication
- Secure communication with APIs
- Protection of OAuth credentials and tokens
- Logging and monitoring
- Secure hosting practices
- Limiting access to what each person or system needs (least privilege), where applicable
No internet-based service can guarantee absolute security, and we cannot promise that information will never be accessed, lost, or disclosed without authorization. If you suspect a security problem, contact [PRIVACY EMAIL].
16. OAuth and account connections
- We may store OAuth credentials or tokens when necessary to maintain your connection to Instagram.
- Tokens are used to communicate with Meta/Instagram APIs on your behalf for the features you enabled. We do not use them for unrelated purposes.
- You can disconnect your account. How completely and how quickly this takes effect depends on our implementation and on Meta's authorization mechanisms.
- [TOKEN STORAGE DETAIL: describe how tokens are protected only once implemented.]
17. Cookies and tracking
| Type | Use | Status |
|---|---|---|
| Essential cookies/storage | Authentication, session management, and service operation | [CONFIRM] |
| Security-related technologies | Fraud and abuse prevention, protecting the Service | [CONFIRM] |
| Preference technologies | Remembering settings such as display preferences | [CONFIRM IF USED] |
| Analytics technologies | Understanding how the Service is used | [CONFIRM IF USED AND WHICH TOOL] |
Essential cookies are required for the Service to work. If we use analytics or other optional technologies, we will describe them here and offer choices where required by law. [COOKIE CONTROLS: describe how users can manage cookies, once decided.]
18. Your rights
Depending on applicable law and your circumstances, you may have rights to:
- Access information we hold about you
- Correct inaccurate information
- Delete your information
- Withdraw consent, where we rely on consent
- Object to or restrict certain processing, where applicable
- Raise a grievance or make a privacy request
To exercise these rights, email [PRIVACY EMAIL] or use [DATA DELETION REQUEST METHOD] for deletion requests. We may need to verify your identity, and we may decline requests where the law allows or requires. These rights vary by jurisdiction and do not apply in every case. If you are a commenter, see Commenter information.
19. Children's privacy
SafeCommet is a general-purpose SaaS product and is not intentionally designed to collect personal information from children where that is prohibited by applicable law. If you believe a child's information has been provided to us in violation of the law, contact [PRIVACY EMAIL] and we will take appropriate steps.
20. International data processing
Our service providers may process data outside India. Your information may therefore be processed in jurisdictions other than where you live, subject to applicable law. We do not claim that data is stored exclusively in India.
21. Changes to this Privacy Policy
We may update this policy as the Service evolves. The "Last Updated" date shows when it last changed. For material changes, we may notify you by email, an in-app notice, or a notice on the website, as appropriate. Continued use of the Service after an update means the updated policy applies, to the extent permitted by law.
22. Contact us
Business/operator: KANBS
Privacy contact: [PRIVACY EMAIL]
Website: [WEBSITE URL]
23. Meta/Instagram disclaimer
SafeCommet is an independent application. It is not affiliated with, endorsed by, or sponsored by Meta Platforms, Inc., Instagram, or their affiliates. Instagram and Meta names are used only to describe compatibility and the integration.