JAVOB
Privacy policy
Last updated: 2026-09-19
Commently is operated by Samadjon Sayfullayev. It helps businesses and creators read public comments on their own Instagram professional accounts, Facebook Pages and YouTube channels, draft replies grounded in information they provide, and publish replies they approve. Contact: samadjonsayfullayev3106@gmail.com.
Information we process
- Workspace accounts: email address and a salted password hash (scrypt). Passwords are never stored in readable form.
- Connected social accounts: the account or Page/channel identifier and name, and the access and refresh tokens you authorize. Tokens are encrypted at rest (AES-256-GCM) and used only by our server.
- Comments: public top-level text comments on posts of the accounts you connect: comment text, the commenter's public display name, and time. We do not collect private profiles or comments on accounts you have not connected.
- We do not collect direct messages.
- Replies and drafts generated or written in Commently, and the platform ID of published replies.
- Business knowledge you enter or upload (for example services, prices, opening hours). Uploaded files are converted to text; the original file is not kept.
- Operational records: request logs (method, path, status, timing), an audit trail of actions, and daily usage counts. Logs exclude tokens and comment text.
How we use it
Only to provide Commently to the workspace that connected the account: collecting comments, drafting replies, publishing replies you approve, showing activity, and keeping the service secure. We do not sell data, use it for advertising, or build profiles of commenters.
Service providers
- OpenAI receives a comment's text together with the relevant profile's business knowledge to draft a reply. Requests are made through the OpenAI API with storage disabled (
store: false); OpenAI's API data-usage policies apply. - Meta and Google platform APIs are used to read comments and publish replies on your behalf.
- Our hosting provider stores the database and backups.
- If the operator enables them, an email provider delivers account messages, and a chat service (for example Telegram or Slack) receives technical alerts. Alerts carry workspace names and identifiers only, never comment text or account passwords.
Google and YouTube data
Commently's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Commently uses YouTube API Services; by connecting a channel you agree to the YouTube Terms of Service, and Google's handling of data is described in the Google Privacy Policy. You can revoke Commently's access at any time at Google security settings.
Retention and deletion
Comments that have been answered or ignored are deleted 30 days after they were completed; only a one-way hash of the comment ID is kept to prevent re-importing it. Any comment is deleted at the latest 365 days after it arrived, even if nobody answered it. Disconnecting an account immediately deletes its tokens and comments from Commently. Deleting a profile or workspace deletes its knowledge, connections and comments. We keep the most recent 14 backups, which is about 14 days on the default daily schedule; older backups are deleted, and then removed. Replies already published remain on the social platform. You can delete any reply Commently published from the platform itself, using the delete button on that reply in Commently, or in the platform's own app. See data deletion.
Security
Access requires a signed-in session over HTTPS. Each customer workspace uses a separate database. Social tokens are encrypted, and administrative sign-in can require two-factor authentication.
What the operator can see
Samadjon Sayfullayev administers this service. The administration dashboard shows service information only: each workspace's name and sign-in name, the names of connected social accounts, activity counts, storage size and sign-in dates. Comment text, drafts, uploaded knowledge and access tokens are not shown there. As the person who runs the server, the operator can also reset a workspace password and can read the underlying files, so a workspace is protected from other customers, not from the operator; account changes of that kind are recorded in the workspace's activity log.
Your choices
You may request access to, correction of, or deletion of your information by writing to samadjonsayfullayev3106@gmail.com. Commenters who want a comment removed from Commently can contact us with a link to the comment.
We will post changes to this policy on this page.