Privacy Policy
Effective 12 August 2026. This policy explains how Andrei Zolin (“CommentKey”, “we”) handles information when operating the CommentKey Instagram automation and transcription service.
Information we process
- Instagram Professional account identifiers and configuration needed to operate the service.
- Instagram-scoped user identifiers, usernames, comment identifiers, message identifiers, timestamps, lead-delivery status, and—when follower gating is enabled—whether the interacting user follows the connected account.
- When a creator enables link reminders, whether the unique CommentKey delivery link was opened. This event is used only to suppress an unnecessary reminder; CommentKey does not record browsing activity on the destination website.
- Comment or message content transiently while deciding whether to respond, plus outbound message text and API response metadata in operational logs.
- Technical records used for webhook authentication, duplicate prevention, rate limiting, security, and troubleshooting.
- When a creator uses the transcription library: the submitted public Instagram URL, optional Reel label and username, processing status, resulting transcript, and detected duration. Downloaded media and extracted audio are temporary and are deleted after each processing attempt.
Why we process it
We process this information to respond to explicit keyword comments, deliver requested resources, transcribe creator-submitted public videos, suppress reminders after a resource link is opened, honor confirmations and opt-outs, prevent duplicate sends, secure the webhook, comply with platform limits, and diagnose failures. We do not sell personal information or use it for third-party advertising.
Service providers
Information is transmitted through Meta/Instagram and hosted using Railway. Audio extracted for a requested transcription is sent to OpenAI for speech recognition and optional formatting or translation. Creator-requested Reels discovery is provided through Apify. Subscription checkout, billing, invoices, and payment-method management are provided by Stripe; CommentKey does not store full payment-card details. These providers process information under their own terms and privacy commitments. We disclose information when required by law or necessary to protect users and the service.
Retention and security
Application database and operational records are automatically removed after 90 days, unless a shorter period is required by law or a limited record must be retained to resolve abuse, security, or legal issues. Creator access tokens are encrypted before database storage; encryption keys and application secrets are stored as deployment secrets. Webhook signatures are verified and transport uses HTTPS.
Your choices and rights
You can send STOP, UNSUBSCRIBE, or CANCEL to opt out. You may also request access, correction, or deletion using the instructions on our data-deletion page. Rights vary by location.
Contact and changes
Data operator: Andrei Zolin. Privacy requests: privacy@commentkey.app. We may update this policy as the service changes and will revise the effective date when changes are material.