Plain-English privacy
Privacy Notice
What CommentThe.net needs to remember, why we need it, and the choices you have.
Last updated 24 August 2026The short version
We collect only what is needed to run accounts and attach conversations to webpages. We do not sell your personal information, build advertising profiles or use your browsing activity to target adverts.
Information we collect
Comments are public. Do not reveal personal details that could identify you or your location, or disclose somebody else's private information.
- Account information: your email address, chosen nickname, password hash, verification status and acceptance of our Terms.
- Conversations: comments and replies, their dates, and the nickname shown beside them.
- Page information: the public webpage URL and title needed to find the correct conversation.
- Security information: hashed anti-abuse identifiers, approximate request timing, IP-derived security checks and normal server request logs.
Information stored on your device
The extension uses Chrome's local storage to remember your sign-in token, draft comments, popup size, account-flow progress and your last-used email address. This is essential to keep you signed in and prevent drafts vanishing. The public website does not currently use analytics or advertising cookies. Cloudflare may use strictly necessary security storage when protecting the service and completing the human check.
How we use information
- To create and secure your account and send verification or password-reset codes.
- To display the correct discussion for the webpage you are visiting.
- To let you edit or delete comments that belong to you.
- To prevent spam, automated signups, flooding, fraud and misuse.
- To investigate reports, maintain the service and comply with legal obligations.
These uses are necessary to provide the service you request, protect the service and its users, and meet our legal responsibilities.
Who processes information
We use a small number of service providers:
- Hostinger hosts the CommentThe.net API and database.
- Cloudflare provides DNS, traffic protection and the Turnstile human check.
- Resend delivers account verification and password-reset emails.
- OpenAI checks submitted nicknames, comments and edits for abusive or unsafe content.
- Google distributes the extension through the Chrome Web Store.
Providers process only the information required for their role. Some may process information outside the UK under their own data-protection safeguards. We may also disclose information where required by law or necessary to protect people and the service.
Retention and deletion
- Account sessions expire after 90 days and can be ended sooner by logging out or changing your password.
- Verification and password-reset codes expire after 15 minutes.
- Comments remain until you delete them, we remove them, or the service is closed.
- Deleting your account removes its email, password and sessions.
- When deleting an account, you choose whether to remove your comment text or retain it under the label Deleted user. A short [Comment deleted] marker may remain where removing the whole record would orphan another person's reply.
- You can also delete individual comments from the extension.
Your choices and rights
Depending on the law that applies to you, you may ask for access, correction, deletion, restriction, portability or to object to certain processing. You can delete comments and your account inside the extension. For other privacy requests, use the developer contact shown on CommentThe.net's official Chrome Web Store listing. UK users can also complain to the Information Commissioner's Office.
Chrome Web Store Limited Use
The use of information received from Google APIs will adhere to the Chrome Web Store User Data Policy, including the Limited Use requirements.
Changes to this notice
We will update this page before introducing materially different data uses, such as an analytics provider. Important changes will also be explained inside the extension where appropriate.
