1. Scope and our role
This Privacy Policy explains how Komment AI Inc. (“Komment,” “we,” “us,” or “our”) collects, uses, discloses, and otherwise processes personal information in connection with our websites, hosted applications, cloud services, accounts, and cloud functionality accessed through a Komment command-line interface (collectively, the “Services”). It also explains the choices and rights that may be available to you.
“Personal information” means information that identifies, relates to, describes, or can reasonably be linked with an individual. It does not include information that applicable law excludes from that definition, such as information that has been deidentified so that it cannot reasonably be linked to an individual.
Komment generally acts as a controller for information used to operate our business and Services, such as account, billing, website, security, and support information. When we process repository content or other data submitted by a customer on the customer’s behalf, Komment may act as the customer’s processor or service provider. Section 7 explains this distinction.
This Privacy Policy does not govern an organization’s independent handling of personal information, third-party products or websites, or locally installed software when it operates entirely on your device without communicating with the Services. When the local CLI connects to the Services, the information transmitted to the Services is covered by this Privacy Policy.
Our Terms of Service govern use of the Services. If you use the Services for an organization, its administrators may control your workspace and Customer Content and may have their own privacy obligations to you.
2. Personal information we collect
The information we collect depends on how you interact with Komment.
Account and profile information
We collect information such as your name, email address, avatar, account role, preferences, verification status, and account timestamps. If you use password authentication, we store a cryptographic password hash rather than your plaintext password.
Authentication and integration information
If you sign in with or connect a third-party service, we receive information authorized through that service. For GitHub or Google sign-in, this can include a provider identifier, username, name, email address, and profile image. If you connect a repository, we process repository identifiers, owner and repository names, URLs, branches, visibility, provider metadata, and an access token or similar credential needed to maintain the connection. We protect stored repository tokens using encryption.
Workspace and administration information
We collect workspace membership, invitations, roles, permissions, repository grants, administrative actions, and information about the users who initiate scans, publish reports, or perform other workspace actions. Authorized Komment personnel may use controlled administrative access, including impersonation functionality where available, for support, security, abuse prevention, maintenance, and legal compliance.
Customer Content and scan data
“Customer Content” includes repositories, source code, files, configuration, prompts, and other material submitted to or accessed by the Services for you. A repository can contain commit history, contributor names and email addresses, dependencies, secrets, credentials, third-party material, and other personal or confidential information.
We also process scan configuration, branches and commit hashes, languages, progress and task state, token and cost information, timing, logs, errors, and the identity of the initiating user. Scan results may include findings, evidence, file paths, source locations, snippets, grades, scores, recommendations, summaries, diagrams, and reports (“Output”).
Billing and transaction information
For paid plans, we process plan, entitlement, billing-cycle, subscription, usage, quota, transaction, and payment-status information. Our payment processor receives the payment-card and billing details needed to complete the transaction. Komment retains processor-issued customer, subscription, and transaction identifiers, but not complete payment-card numbers.
Communications and marketing information
We collect information you provide when you contact support, report a security or legal issue, respond to a survey, request information, join an early-access list, or otherwise communicate with us. This can include your contact information, organization, job-related information, message contents, attachments, preferences, and communication history.
Website, device, session, and usage information
When you use the Services, we and our hosting and security providers automatically receive technical information such as IP address, request time, page or endpoint requested, browser or client type, operating-system information available through the client, session identifiers, referring page, error data, and activity associated with your account. We use IP addresses to derive approximate country, region, or city and, when configured, to identify likely VPN or proxy traffic. The Services do not collect precise GPS location.
We use cookies or similar browser storage for authentication, session continuity, security, and preferences. Section 8 provides more information.
3. Where personal information comes from
We collect personal information:
- directly from you, including through registration, settings, checkout, support, and communications;
- from your organization and its workspace owners or administrators;
- from third-party identity and repository providers, including GitHub and Google, according to the permissions you authorize;
- from repositories and other Customer Content connected to or submitted through the Services;
- automatically from your browser, device, CLI, and use of the Services;
- from payment, email-delivery, infrastructure, security, fraud-prevention, and IP-intelligence providers; and
- from public sources when you ask us to analyze a public repository or when reasonably necessary to protect and operate the Services.
If you provide personal information about someone else, you are responsible for having the authority and providing any notice required to let Komment process it as described here.
4. How we use personal information
We use personal information to:
- create, authenticate, secure, and administer accounts and workspaces;
- connect repositories and provide scans, reports, recommendations, and other requested Services;
- route relevant Customer Content to configured model providers for inference;
- calculate usage, administer subscriptions, process payments, and enforce plan limits;
- send verification, password-reset, transactional, security, service, support, and policy communications;
- respond to requests, provide support, and troubleshoot errors;
- detect, investigate, and prevent fraud, abuse, security incidents, unauthorized access, and violations of our Terms;
- monitor reliability, measure performance, allocate infrastructure, debug failures, and improve the Services;
- understand demand for our products and send marketing communications where permitted;
- comply with law, enforce agreements, establish or defend legal claims, and protect users, Komment, and others; and
- complete a financing, merger, acquisition, reorganization, asset transfer, or similar corporate transaction.
We may aggregate or deidentify information and use it for lawful purposes, including service analytics, capacity planning, security research, and product improvement. We do not use private source content in aggregated operational metrics. We do not attempt to reidentify information that we maintain as deidentified unless permitted by law to test our deidentification processes.
5. Repository and AI processing
The Services create a temporary working copy of a connected repository to perform a scan. We remove that working copy from the analysis environment after the scan completes or is stopped through the ordinary workflow. This does not mean that all information derived from the repository is deleted at that time. We may retain project and repository metadata, scan state, findings, evidence, file paths, source locations, snippets, reports, logs, and other Output as described in this Privacy Policy.
Portions of Customer Content, including source code and related context, may be transmitted to a configured machine-learning model provider to generate analysis. The provider, location, and retention behavior can depend on the production route and customer arrangement. Providers acting for Komment are authorized to process that information to provide their services to us under the applicable arrangement.
Komment does not use Customer Content or customer-specific Output to train or fine-tune machine-learning models. We do not permit a model provider acting as our processor to use that content to train its general models. Unless a written order or data processing addendum expressly provides otherwise, we do not promise that every provider offers zero retention.
Automated security analysis is probabilistic and may produce false positives, false negatives, or incomplete results. It is not used by Komment to make decisions about individuals that produce legal or similarly significant effects.
6. How we disclose personal information
We may disclose personal information to the following recipients for the purposes described in this Privacy Policy:
- infrastructure, database, storage, logging, monitoring, security, and support providers that host or help operate the Services;
- model providers that process selected Customer Content for inference;
- identity and repository providers when you authenticate, connect a repository, or direct an integration;
- payment processors, billing providers, and professional advisers involved in subscriptions and transactions;
- email-delivery, customer-communication, fraud-prevention, and IP-intelligence providers;
- your organization, workspace owners and administrators, and other users authorized to access the relevant workspace, repository, scan, or report;
- the public when an authorized user affirmatively publishes a report or otherwise directs public disclosure;
- auditors, lawyers, accountants, insurers, financing sources, and similar advisers subject to appropriate duties;
- law-enforcement, regulators, courts, government authorities, or other parties when we reasonably believe disclosure is required by law or necessary to protect rights, safety, security, and the integrity of the Services; and
- a prospective or completed acquirer, investor, lender, successor, or transaction participant in connection with a financing, merger, acquisition, reorganization, bankruptcy, asset sale, or similar transaction, subject to appropriate protections.
We do not sell personal information for money. We do not share personal information for cross-context behavioral advertising or process it for targeted advertising as those terms are defined under applicable US state privacy laws. If those practices change, we will update this Privacy Policy and provide any notice and choice required by law before the change applies.
7. Business customers and Customer Content
An organization generally determines which repositories and other Customer Content its users submit, who can access its workspace, why that content is processed, and how long it should be kept. For personal information contained in Customer Content, Komment generally processes the information on the organization’s behalf as its processor or service provider. The organization is responsible for its instructions, permissions, notices, legal basis, and responses to individuals. Our Data Processing Addendum governs that processing when it applies.
If your information appears in Customer Content submitted by one of our customers, direct your request to that customer when practical. We will assist the customer as required by our agreement and applicable law. We may tell you which customer controls the information when we can do so without compromising another person’s rights or security.
Komment remains a controller for information we use for our own operational purposes, such as account administration, billing, service security, fraud prevention, legal compliance, and our direct relationship with you.
8. Cookies and similar technologies
Komment uses cookies and similar browser technologies that are necessary to authenticate users, maintain sessions, and protect the Services. For example, the hosted application uses an HTTP-only authentication cookie and a separate session-metadata cookie. Our Cookie Policy identifies the current technologies, purposes, and durations.
As of the effective date, the Services do not use third-party advertising cookies or behavioral-advertising technology. We will not introduce nonessential analytics or advertising technologies without making the disclosures and providing the consent or opt-out controls required by applicable law.
You can configure your browser to block or delete cookies, but blocking necessary cookies may prevent account sign-in or other Services from working. Where required, we will honor applicable browser-based universal opt-out signals. Because we do not currently sell personal information, share it for cross-context behavioral advertising, or process it for targeted advertising, such a signal does not otherwise change those practices.
9. Public reports
Reports are private to you or your workspace by default. A public repository does not automatically make its Komment report public.
If an authorized user affirmatively publishes a report, the report may expose the repository name and metadata, findings, evidence, grades, file paths, source locations, source excerpts, and other information contained in the selected report. The publishing user and customer are responsible for reviewing the report and confirming that they have authority to make that information public.
Public information may be viewed, copied, indexed, cached, or redistributed by search engines and other third parties outside Komment’s control. If an authorized user later withdraws publication, we will stop making the report publicly available through the ordinary Services, but copies or caches held by others may remain. Contact privacy@komment.ai if a public report exposes personal information or should be reviewed for removal.
10. How long we retain information
We retain personal information for as long as reasonably necessary for the purposes described in this Privacy Policy. The applicable period depends on the type of information, the customer’s instructions and plan, the sensitivity of the information, operational needs, and legal requirements.
In general:
- account, profile, workspace, and subscription information is kept while the account or customer relationship remains active and for a reasonable period afterward;
- temporary repository working copies are removed after the scan completes or is stopped through the ordinary workflow, while retained findings, snippets, reports, logs, and related artifacts follow their own lifecycle;
- Customer Content and Output are retained according to available customer controls, the customer agreement, and our backup and deletion processes;
- security, audit, and service logs are kept long enough to protect, troubleshoot, and maintain the Services and investigate abuse;
- billing and transaction records are retained as needed for accounting, tax, dispute, and legal obligations;
- support and legal communications are retained while needed to resolve the matter and establish or defend rights; and
- marketing-contact information is retained until you opt out or it is no longer useful, subject to a limited suppression record needed to honor your choice.
Deletion may not immediately remove information from encrypted backups, disaster-recovery systems, security records, or model-provider systems. Information remaining in routine backups is isolated from ordinary use and deleted or overwritten through the applicable rotation process. We may retain information longer when required by law, subject to a legal hold, needed to resolve a dispute, or necessary to prevent fraud or abuse.
We will deidentify or delete personal information when it is no longer reasonably necessary, subject to these qualifications. Account closure or repository disconnection does not necessarily delete every associated record immediately.
11. Legal bases for processing
If the European Economic Area, United Kingdom, or another jurisdiction requiring a legal basis applies, our legal bases depend on the context:
- Contract: to create and administer an account, provide requested scans and reports, process a subscription, provide support, and perform our Terms or an Order;
- Legitimate interests: to secure and improve the Services, prevent fraud and abuse, communicate with customers, administer our business, understand service performance, and establish or defend legal claims, where those interests are not overridden by your rights;
- Consent: where we ask for consent, including for certain marketing or nonessential cookies if introduced; and
- Legal obligation: to comply with tax, accounting, sanctions, law-enforcement, regulatory, and other legal duties.
Where we rely on consent, you may withdraw it at any time without affecting processing that occurred before withdrawal. Where we rely on legitimate interests, you may have a right to object. We do not intentionally require special-category or similarly sensitive personal information to provide the ordinary Services. If a customer includes such information in a repository, the customer is responsible for having an appropriate legal basis, and we process it to provide and secure the Services under the applicable customer arrangement.
12. International data transfers
Komment is based in the United States. We and our providers may process personal information in the United States and other countries where we or they operate. Those countries may have privacy laws that differ from the laws where you live.
Where applicable law requires a transfer mechanism, we use an approved mechanism appropriate to the transfer, such as the European Commission’s Standard Contractual Clauses, the UK International Data Transfer Addendum, or another legally recognized safeguard. We also evaluate providers and apply contractual, organizational, and technical protections appropriate to the information and processing.
13. Security
We use technical and organizational measures designed to protect personal information against unauthorized access, loss, misuse, alteration, and disclosure. Our measures include access controls, role-based workspace permissions, encryption of stored repository tokens, encrypted network transport, restricted administrative functionality, logging, and separation of temporary repository working copies from retained service records.
No security measure or transmission method is completely secure. You are responsible for protecting your credentials and devices, configuring workspace access, limiting the information placed in repositories, and reviewing a report before making it public. Notify security@komment.ai if you believe an account, token, or the Services have been compromised.
14. Your privacy rights and choices
Depending on where you live and subject to legal exceptions, you may have the right to:
- know whether we process your personal information and access or obtain a copy of it;
- request correction of inaccurate personal information;
- request deletion of personal information;
- obtain certain information in a portable format;
- object to or request restriction of certain processing;
- withdraw consent where processing is based on consent;
- opt out of sale, targeted advertising, or qualifying profiling;
- limit certain uses and disclosures of sensitive personal information;
- appeal our refusal to act on a request; and
- receive equal service and pricing without unlawful discrimination for exercising a privacy right.
To exercise a right, email privacy@komment.ai and describe your request. No special form or wording is required. If you already have an account, write from its registered email when practical. We may ask for information reasonably necessary to verify your identity, locate the relevant records, protect other people, and confirm an authorized agent’s authority. We will not require you to create a new account solely to make a request.
Some information may be exempt from a request—for example, when retention is required by law, needed for security or fraud prevention, or necessary to establish or defend legal claims. If we deny a request in whole or in part, we will explain our decision as required by law.
To appeal an eligible decision, reply to our decision or email privacy@komment.ai with “Privacy Appeal” in the subject line. We will respond within the period required by applicable law and, where required, explain how to contact the relevant regulator.
You can unsubscribe from marketing email through the link in the message or by contacting us. You may still receive account, security, billing, support, and other non-marketing communications. You can manage certain profile and workspace information through available account settings.
15. Additional regional disclosures
This section supplements the rest of this Privacy Policy for residents of jurisdictions with comprehensive privacy laws, including California and other applicable US states.
Categories of personal information
Depending on how you use the Services, we collect the following categories:
- Identifiers and contact information: name, email address, account and provider identifiers, username, IP address, and similar identifiers;
- Customer-record and commercial information: organization, subscription, plan, transaction, payment status, billing, support, and customer-relationship information;
- Internet, device, and network activity: session, browser, device, request, interaction, security, log, and diagnostic information;
- Professional or employment-related information: organization, role, job-related contact information, and repository contributor information;
- Approximate geolocation: country, region, or city inferred from an IP address;
- Account access and other sensitive personal information: account credentials, authentication information, and access tokens, and sensitive information that a customer may include in Customer Content; and
- Content, communications, and derived information: support messages, repository and source content, prompts, scan data, findings, evidence, snippets, reports, scores, and related Output that identifies or can reasonably be linked to a person.
We collect these categories from the sources described in Section 3, use them for the purposes in Sections 4 and 5, and disclose them to the recipient categories described in Section 6. We retain them according to Section 10.
We use sensitive personal information only to provide and secure the Services, maintain account access, prevent fraud, comply with law, and perform other purposes permitted without a right to limit under applicable law. We do not use sensitive personal information to infer characteristics about individuals.
We have not sold personal information or shared it for cross-context behavioral advertising, and we have not processed it for targeted advertising. We do not knowingly sell or share the personal information of anyone under 18. Service-provider disclosures described in Section 6 are made for business purposes and are not a sale when the recipient is contractually restricted as required by law.
Where applicable, you may exercise the rights described in Section 14 personally or through an authorized agent. Before responding to requests for specific information, correction, or deletion, we may match information you provide against our records and use account or email verification. For an agent, we may require proof of authorization and direct confirmation from you unless a power of attorney or applicable law provides otherwise.
16. Children
The Services are intended for people who are at least 18 years old and are not directed to children. We do not knowingly collect personal information directly from anyone under 18 through an account.
A customer repository may incidentally contain information about a minor. In that situation, we process the information on the customer’s behalf, and the customer is responsible for having authority to submit it. If you believe a minor has provided personal information to us or that Customer Content processed by Komment improperly contains a minor’s information, contact privacy@komment.ai.
17. Third-party services
The Services may link to or interoperate with third-party services. If you authorize GitHub, Google, a repository host, or another third party, that party handles information under its own privacy policy as well as any role it performs for Komment. We are not responsible for a third party’s independent products, websites, or privacy practices.
Review the permissions shown by a third party before connecting it. You can revoke some integrations through the third party or available Komment settings, although revocation does not automatically delete information previously processed or retained under this Privacy Policy.
18. Changes to this Privacy Policy
We may update this Privacy Policy as the Services, providers, and legal requirements change. We will post the updated policy and revise the effective date. If a change materially affects how we use personal information or materially reduces your rights, we will provide additional notice through the Services, by email, or another appropriate method when required.
Where law requires consent for a new use, we will request it before that use begins. We retain previous versions as part of Komment’s policy-version records.
19. Contact us
For privacy questions or to exercise a privacy right, contact:
Komment AI Inc., 251 Little Falls Drive, Wilmington, DE 19808
privacy@komment.ai
The email address above is active and monitored. Individuals in the European Economic Area or United Kingdom may also lodge a complaint with the data-protection authority where they live or work. Residents of a US state with an appeal right may use the appeal process in Section 14 and, if an appeal is denied, contact the regulator identified in our response.