Privacy policy
Updated October 1, 2026
Your exports stay in your browser, and we only see comment text when you ask for an AI brief, which we pass to a model provider and don't store. This page lists everything we do collect, who processes it for us, how long we keep it and how to delete it.
Who we are
Comment Scraper is a browser extension for Chrome and Edge and the website comment-scraper.com. Both are run by [LEGAL ENTITY], [ADDRESS] ("we", "us"). For anything about privacy, email hello@comment-scraper.com.
The short version
- Exports are stored only in your browser and deleted after 30 days. We never receive them.
- Exports don't include author fields. Usernames that people typed inside a comment are kept as written.
- When you run a hosted AI brief, the comment text goes through our server's memory to a model provider and the result comes back to you. We don't write it to disk or keep it.
- We collect your email address, your plan and credit records, usage counts, anonymous failure counts and a small set of product events.
- We don't collect your browsing history. We don't sell data. We don't use comment text for anything except the brief you asked for.
Where comment text goes
| What you do | Who handles the comment text | What is kept |
|---|---|---|
| Export only | Only your browser | Stored in the extension's local database (IndexedDB) and deleted after 30 days |
| Hosted AI brief | Your browser, then our server (in memory only), then the model provider, then back to your browser | We don't write comment text to disk. Our application logs and error reports never contain comment text; they record the request ID, your user ID, token counts, timing and error codes. |
Exports stay in your browser
When you export a thread, the extension saves the result in your browser's extension storage (IndexedDB). An export contains the thread title, comment text, scores, timestamps, reply structure and links. It contains no author fields.
Each saved export is deleted automatically 30 days after you made it, and the extension reminds you 3 days before. It also keeps only your most recent exports (10 on Free, 50 on paid plans, 200 MB at most) and removes the oldest when you go over.
We can't see your exports. Files you download or copy are on your computer and outside our control.
To make sure a paused export resumes in the same Reddit session, the extension stores a one-way hash of your Reddit username in its local storage. It is never sent to us.
AI briefs
When you ask for a hosted brief, the extension sends the text of the comments being analysed, with their comment IDs so the brief can point back to them. It doesn't send author fields. Usernames typed inside comment text are sent as written, because we don't change comment text.
The request goes to our server, which holds it in memory only and forwards it to OpenAI's API, our model provider. OpenAI says data sent to its API is not used to train or improve its models unless the customer opts in (we haven't), and that it keeps API abuse-monitoring logs for up to 30 days (OpenAI: your data, checked 2026-10-01). The brief comes back to the extension and is stored with its export in your browser.
We don't store the comment text, the per-chunk summaries or the finished brief on our servers. We don't sell it, we don't use it to train models and we don't use it for anything other than producing the brief you asked for. Per-chunk summaries are cached in your browser so an interrupted brief can pick up where it left off.
Before your first hosted brief, the extension shows a dialog explaining this and naming the provider, and nothing is sent until you agree. You can turn off hosted briefs in settings at any time.
What we collect
Account
Your email address. We use it to send sign-in codes and messages about your account or billing. You only need an account for AI briefs and paid plans. Exports work without one.
Plans, credits and payments
Your plan, its status and dates, and the Stripe subscription or payment ID that goes with it. A ledger of your credits: when they were granted, used and when they expire. For each brief, a record with the request ID, its status, credits reserved and charged, how many chunks were processed, token counts and the time. To stop a request ID being reused for different content, we also store a one-way hash of each chunk. A hash can't be turned back into the text, and we store no comment content.
Usage counts
How many briefs you've run and how many credits you've used, so we can apply your plan's limits.
Anonymous parse-failure counts
So we notice quickly when Reddit changes its pages, the extension reports hourly counts of successful and failed exports. Each count includes the parse path (Reddit's JSON or the page itself), the selector version and a comment-count range. It includes no URLs, no content and nothing that identifies you. You can turn this off in settings.
Product events
The extension creates a random install ID. It has nothing to do with your Reddit account. When you sign in, we link it to your user ID. We record only these events:
installexport_completed, with the source site, how the export ended and a comment-count rangebrief_completedupgradeaccount_warning_reported, when you click the button saying you got a warning from Reddit
Events don't include thread URLs or content. You can turn off this reporting in settings.
Settings the extension downloads
Every few hours the extension downloads a signed settings file from our server. It holds the page selectors, rate limits and on/off switches for each source. This request carries no Reddit data.
Sign-in rate limits
When you ask for a sign-in code, we store a salted one-way hash of your IP address and of your email address, with the time. We use them only to limit how many codes and new accounts one address can request, which stops people from farming free briefs. The hashes can't be turned back into the address.
Website
We use Vercel Analytics to count visits to comment-scraper.com. It doesn't use cookies. If you sign in on the website to manage your account, your browser keeps a sign-in token so you stay signed in.
What we don't collect
- Your browsing history, or any page other than the thread you choose to export
- Your Reddit password or Reddit username (only the local hash described above, which never leaves your browser)
- Author fields from threads
- Your card number, which goes to Stripe and never reaches us
We don't sell personal data. There are no ads on the site or in the extension.
Who processes data for us
| Provider | What for | What they receive |
|---|---|---|
| Stripe | Payments, invoices, the billing portal and tax | Your email and the payment and billing details Stripe needs. Card details go to Stripe, not to us. |
| Resend | Sending email | Your email address and the message |
| Vercel | Hosting the website and our API, including the brief endpoint; website analytics | Requests to our site and API. During a brief, the comment text passes through in memory. |
| OpenAI | Generating AI briefs | Comment text and comment IDs for that brief |
Our database runs on our own server, not a third-party database service. It holds your account, plan, credits, usage, events and failure counts. It holds no comment content.
How long we keep things
- Exports in your browser: 30 days, or until you delete them.
- Comment text on our servers: not kept. It exists in memory only while a brief runs.
- Account, plan, credit and usage records: until you delete your account.
- After you delete your account: the Stripe transaction ID, amount and date of each payment, for tax and refunds. We don't keep your email with them.
- Stripe keeps its own payment records under its own privacy policy.
Deleting your data
In the extension's settings, "Delete all local data" removes every export and brief stored in your browser. Uninstalling the extension also removes its local storage.
To delete your account, use the delete option in your account settings or email hello@comment-scraper.com from the address on the account. We first cancel your Comment Scraper subscription, if you have one, and then delete your account, plan records, credits and usage records. We keep only the Stripe transaction ID, amount and date described above.
You can also email us to ask what account data we hold about you, or to correct it.
Changes to this policy
If we change what we collect or who processes it, we'll update this page and the date at the top before the change takes effect.
Contact
[LEGAL ENTITY], [ADDRESS]. Email: hello@comment-scraper.com.