Your data. Your choices.
How CommentCare handles personal data when you visit, create an account or connect TikTok.
1. Who is responsible.
Theodor Conrad Borth operates CommentCare from Zehenthofgasse 37, 1190 Wien, Austria. Contact: hello@commentcare.app. CommentCare is the new name of Stillkind and is not a separate legal entity. Our TikTok integration continues to appear as Stillkind.
We act as controller for our website, account administration, security and support. When we moderate a connected creator’s comments on their documented instructions, the creator determines the moderation purpose and is the controller; CommentCare acts as processor. Our separate Data Processing Agreement covers that relationship and is accepted before TikTok processing starts or resumes. This notice does not replace that agreement.
2. Data we receive and where it comes from.
You provide your email address, password and support messages directly. We store a password hash, not the readable password. Browsers and hosting services provide technical information such as IP address, request time, browser details and error information.
After you authorize TikTok, its API supplies account identifiers and username; access and refresh tokens; video identifiers, captions, thumbnail URLs, publication times and comment counts; and available comments and replies, including identifiers, text, usernames, timestamps and visibility. These comments originate from people using TikTok, who may not have a CommentCare account.
We create scan status, usage counts, protection preferences and moderation records, including AI categories, confidence scores and hide/restore outcomes. Providing account details is necessary to create an account; connecting TikTok is necessary to use moderation. You can browse public pages without connecting.
3. Why we process information.
Account creation, authentication, requested support and delivery of the service rely on performance of a contract or requested pre-contractual steps (Article 6(1)(b) GDPR). General business enquiries and operational security rely on legitimate interests in responding to messages, preventing abuse and keeping the service reliable (Article 6(1)(f)). Applicable record-keeping obligations rely on Article 6(1)(c).
For moderation performed on behalf of a creator, we follow their instructions. The creator must identify a lawful basis and provide required information to their commenters. Connecting through OAuth is technical authorization; it is not consent from everyone who comments.
We do not sell comment data, use it to build advertising audiences or use it to train our own AI models. We do not currently run advertising pixels or visitor analytics.
4. How AI moderation works.
OpenAI’s API receives batches containing comment text, commenter usernames, internal comment identifiers and the related video caption and video identifier. We do not send passwords, TikTok access tokens, video files or audio to the classifier. AI output includes an action, category, confidence score and optional protection signals.
The first check analyzes available comments on the latest 20 videos without hiding anything. Once setup is complete, high-confidence matches can be hidden under the selected rules. False positives and missed spam are possible. Creators can inspect the activity and request restoration; commenters can request review by contacting the creator or us.
This is automated content moderation, not a system intended to decide eligibility for employment, credit, healthcare or similar significant matters. A confidence score is not a guarantee of accuracy.
Classification uses the Responses API with storage of application state disabled. OpenAI states that API inputs and outputs are not used for training by default. Abuse-monitoring records may still be retained for up to 30 days, or longer where legally required. We do not claim Zero Data Retention.
5. Recipients and international processing.
Vercel hosts the website and server-side frontend. Railway hosts the API and PostgreSQL database; the deployed backend and database are in Amsterdam. OpenAI supplies AI classification. TikTok supplies authorized account data and receives moderation requests. Namecheap forwards domain email to the operator’s Gmail inbox, processed by Google.
Authorized operator access is limited to operating the service, handling support and meeting legal duties. Information may also be disclosed to professional advisers or authorities where necessary and legally justified. When you choose a paid plan, Stripe processes your checkout, payment details, billing address and tax information. We send Stripe your account email and an internal account identifier, and retain customer/subscription identifiers and payment status to manage access. Card details are entered on Stripe and are not stored by CommentCare. Google/Apple sign-in remains unavailable unless explicitly enabled.
An EU database location does not make the entire service EU-only. Hosting delivery, AI processing, email and provider support can involve countries outside the EEA, including the United States. The applicable processor contracts and transfer arrangements must cover each service. We have not represented that all account-specific agreements and safeguards have been verified. Contact us for the current documented arrangements; provider privacy policies alone are not a substitute for a lawful transfer mechanism.
6. Retention and removal.
Settings provides a JSON export of the application data associated with your account. The export excludes password hashes, API tokens and session secrets. Contract-version acceptance is recorded with your account ID and timestamp; IP addresses are not added to that record. A separate deletion ledger retains only the deleted internal account ID and deletion time so restored backups can be screened before use; it is retained until affected backups have expired and deletion checks are complete.
Account records are held while your CommentCare account exists. An hourly retention task removes processed comment text, commenter usernames and detailed detection signals once 90 days have passed since collection. Comments awaiting processing are excluded until their pending action is resolved. Minimal comment IDs, video references and decision metadata remain while the connection exists to prevent duplicate scanning and charging. These identifiers remain personal data; this is minimization, not anonymization. Imported video metadata remains for monitoring until disconnection. Disconnecting deletes the connection, tokens, videos and comments from the active database. Account-level usage records can remain until full account deletion.
Application sessions expire after at most 30 days and are invalidated by logout. Temporary authorization and password-reset records have short expiry times and are cleaned up at least hourly, independently of the scanning worker. Provider operational logs and backup copies have separate retention arrangements; a uniform verified backup deletion deadline has not yet been established.
For support correspondence, we assess continued need by the unresolved enquiry, evidence needed for a dispute and applicable statutory obligations. We do not promise immediate erasure from every provider system. In response to a verified deletion request, we identify the affected active records, backup copies and provider records and explain any lawful exceptions or remaining retention.
8. Your rights and how to exercise them.
Where the relevant conditions apply, you may request access, correction, erasure, restriction and data portability. You can object to processing based on legitimate interests on grounds relating to your situation. If processing relies on consent, you can withdraw it without affecting earlier lawful processing. We do not currently use your data for direct marketing.
Email hello@commentcare.app. We may request only proportionate information to verify identity and locate records. Requests are generally free and answered without undue delay, normally within one month. For a permitted extension of up to two additional months, we explain the reason within the first month. Refusals must also be explained, including the available remedies.
Commenters can contact the creator directly or send us the creator username, video link and identifying comment details. You do not need a CommentCare account. When the creator is controller, we assist them with the request.
9. Age, security and updates.
CommentCare accounts are intended for adults. Comments can nevertheless include information about minors. Do not deliberately submit sensitive information unrelated to moderation. Contact us if information about a child needs review.
Passwords are hashed, stored TikTok tokens are encrypted, and access to account data is authenticated. These measures do not guarantee absolute security. Report suspected incidents through our contact page without sending credentials.
The date above identifies this notice version. We will communicate material changes through the service and, where appropriate, directly to account holders before new processing begins.