Privacy Policy
Last updated: 19 September 2026
This policy explains what personal data EveryComment handles, why, who else is involved, and what your rights are. It is written to be read.
The short version: we hold your team’s sign-in details and the comments and messages from the accounts you connect, so your team can answer them. We do not sell data. We do not use it for advertising. AI drafts are only ever sent after a person approves them.
1. Who we are
EveryComment is provided by Paradigm Social Ltd, a UK company trading as EveryComment. For anything about privacy, write to hello@everycomment.ai.
2. Two kinds of data, two roles
Your account data. Details about you and your team as users of EveryComment. For this we are the controller: we decide why and how it is used, as set out in this policy.
Your inbox data. The comments, direct messages and reviews from the social accounts you connect, written by members of the public to you or your clients. For this you are the controller and we are your processor: we handle it only on your instructions, to provide the service. If someone who wrote to a brand asks us about their data, we will pass the request to that brand’s organisation.
3. What we collect
Account data:
- your email address, and the name and profile picture Google gives us if you sign in with Google;
- your organisation’s name, its brands, your role, and your language setting;
- what you do in the product that the product itself needs to record: replies you send, conversations you mark done or assign, drafts you approve, edit or dismiss, and notification settings;
- billing details when billing is enabled: plan, subscription status and a Stripe customer reference. Card details go to Stripe, not to us;
- technical records that our hosting and database providers keep for a short time, such as IP address, browser type and the time of a request.
Inbox data, from the accounts you connect:
- comments, direct messages and reviews, with the public profile name, handle and profile picture of the person who wrote them;
- attachments sent in messages, such as images, which we copy into private storage because the platforms’ own links expire;
- the post or advert a comment was left on;
- the replies your team sends, and any contact details a person chooses to give in a conversation, such as a phone number or email address.
Brand profiles: what you tell the AI about each brand, including text we read from the public website address you give us.
4. Why we use it, and our legal basis
- To provide EveryComment to you (sign-in, the inbox, sending your replies, drafts, notifications, invitations): performance of our contract with you.
- To take payment and keep accounts: contract, and our legal obligations for tax and accounting records.
- To keep the service secure and working (logs, fixing faults, preventing abuse): our legitimate interest in running a safe, reliable service.
- To tell you about important changes to the service or these documents: legitimate interest and contract. We do not send marketing email without your consent.
For inbox data we act on your instructions. You decide the legal basis for handling your own audience’s messages.
5. AI
When a draft is written, the conversation being answered and the brand’s profile are sent to Anthropic through its API, and the draft comes back. The same provider is used to suggest a brand profile from your website and to turn your team’s edits into guidance for later drafts for that brand.
- Nothing the AI writes is sent until a person on your team approves it. There is no automatic sending.
- We do not use your inbox data to train our own models, and what is learned from one organisation’s edits is used only for that organisation’s brands.
- Under Anthropic’s commercial terms at the time of writing, content sent through its API is not used to train its models.
- You can switch AI drafting off for a brand in Settings. Conversations for that brand are then not sent for drafting.
No decision with legal or similarly significant effect is made about anyone by automated means.
6. Who else handles the data
We use these companies (sub-processors) to run EveryComment. Each handles data only to provide its part of the service.
| Company | What it does for us | Data involved |
|---|---|---|
| Supabase | Database, file storage and sign-in. Hosted in the EU. | Everything stored in EveryComment: accounts, conversations, attachments, brand profiles. |
| Vercel | Hosting: runs the application and serves its pages. | Everything that passes through the application while it is being handled, and short-lived request logs. |
| Zernio | The connection to the social platforms: receives comments and messages and delivers replies. | Connected account details, access granted to those accounts, and the comments, messages and replies that pass through. |
| Anthropic | AI drafting, suggesting a brand profile from a website, and learning from edits, through its API. | The conversation being answered (which can include names and whatever the person wrote), your brand profile, and drafts with the edits made to them. |
| Resend | Sending email, such as invitations to teammates. | The recipient’s email address, the inviter’s email address and the organisation’s name. |
| Stripe | Payments and subscriptions, when billing is enabled. | Billing contact, plan, and payment details, which go straight to Stripe and never reach us in full. |
The social platforms. Comments and messages come from, and replies go back to, the platforms you connect: Meta (Facebook and Instagram), Google (Business Profile) and TikTok. They are independent controllers of the data on their platforms, under their own terms and privacy policies, which also apply to your connected accounts.
Your browser’s notification service. If you switch on desktop notifications, they are delivered through the push service of your browser’s maker (such as Apple, Google or Mozilla).
Places you choose. If an admin sets up a lead web address for a brand, the details of each lead your team sends, with a short AI summary of the conversation, go to that address. You control where that goes.
We do not sell personal data, and we do not share it with anyone for their advertising. We may disclose data if the law requires it, or to a buyer of the business, who would have to keep to this policy.
7. Where data is held
The database and stored files are hosted in the EU. Some of the companies above are based in, or may process data in, other countries including the United States. Where personal data leaves the UK, we rely on the safeguards UK law allows, such as adequacy regulations (including the UK extension to the EU-US Data Privacy Framework, where the company is certified) or the UK International Data Transfer Agreement or Addendum in our contracts with them.
8. How long we keep it
- We keep account data and inbox data while your organisation has an account, so your team has its history.
- An admin can remove a teammate at any time, which ends their access at once.
- When you ask us to close your organisation, we delete its data, including conversations, attachments, drafts and brand profiles, within 30 days. Copies in routine backups are overwritten within a further 30 days.
- We keep invoices and payment records for as long as tax law requires, which is normally six years.
- Deleting data in EveryComment does not delete the original comment or message on the social platform. That stays under the control of the account owner and the platform.
9. Deleting data on request
Write to hello@everycomment.ai from an admin’s email address and tell us what to delete: a single conversation, everything about one person, a brand, or the whole organisation. We will confirm when it is done. If you need a copy of your data first, ask and we will provide an export in a common format.
10. Security
No service can promise perfect security. These are the measures actually in place:
- all traffic between your browser, EveryComment and the companies above is encrypted in transit (HTTPS/TLS), and our database provider encrypts stored data at rest;
- access is limited by organisation: every request is checked against the signed-in person’s organisation, so one organisation cannot read another’s data, and only admins can change settings, people and billing;
- sign-in is through Google or a one-time emailed link. We do not store passwords;
- incoming webhooks from the connection provider and the payment provider are signed, and we reject any that fail the check;
- message attachments are kept in private storage and shown through short-lived links;
- secrets are kept in the hosting provider’s encrypted configuration, not in the code, and access to production is limited to the few people who run the service.
If a personal data breach affects your organisation’s data, we will tell its admins without undue delay after we become aware of it, with what we know, so you can meet your own obligations.
11. Data processing terms (for inbox data)
This section applies where we process inbox data on your behalf, and forms part of our Terms of Service.
- Subject matter and duration: providing EveryComment, for as long as you have an account.
- Nature and purpose: receiving, storing, displaying, drafting replies to, and sending replies to comments, messages and reviews on the accounts you connect.
- Data subjects: people who comment on, message or review the brands you manage.
- Types of data: public profile name, handle and picture; the content of comments, messages and reviews, including attachments and anything the person chooses to share.
We will:
- process inbox data only on your documented instructions, which are these terms and what you do in the product, unless the law requires otherwise;
- make sure the people who can access it are bound by confidentiality;
- keep the security measures described above;
- use the sub-processors listed above, under contracts that protect the data to the same standard, and remain responsible for them. We will update this page before adding or replacing one, and you may object by writing to us. If we cannot resolve your objection, you may cancel;
- help you, as far as we reasonably can, to respond to people exercising their rights, and with security, breach notification and impact assessments;
- tell you without undue delay about a personal data breach affecting your inbox data;
- delete or return inbox data when the service ends, as described above, unless the law requires us to keep it;
- give you the information reasonably needed to show we meet these obligations.
You are responsible for having a lawful basis for the processing, and for giving your own audience the privacy information the law requires.
12. Cookies
EveryComment uses only the cookies it needs to work: one that keeps you signed in, and one that remembers your language. There are no advertising or tracking cookies, and no third-party analytics.
13. Your rights
Under UK data protection law you have the right to ask for a copy of your personal data, to have it corrected or deleted, to restrict or object to how it is used, and to receive it in a portable form. To use any of these rights, write to hello@everycomment.ai. We will answer within one month.
If you wrote to a brand that uses EveryComment, that brand decides how your message is handled. Contact the brand first. If you contact us, we will pass your request on to them.
You can also complain to the Information Commissioner’s Office, the UK regulator, at ico.org.uk. We would appreciate the chance to put things right first.
14. Children
EveryComment is a business tool and is not meant for anyone under 18.
15. Changes to this policy
We will update this page when what we do changes, and change the date at the top. For a change that matters, including a new sub-processor, we will tell each organisation’s admins by email.
16. Contact
Paradigm Social Ltd, trading as EveryComment: hello@everycomment.ai.