Terms of service
Last updated 14 September 2026.
These terms cover the use of Comment — the dashboard, the API, and the script you install on your website. They are written to be read, not to be survived.
Who you are agreeing with. Comment is an independent product in early
access, operated under the name comment_. The contracting entity, its
registered address, and the governing law and venue that follow from it will be named
here before anything is offered for sale. Until then these terms are the basis on which
free early-access accounts are provided, and the operator answers at
privacy@commentunderscore.com. If you
need a signed agreement with a named counterparty before you can install anything, write
to that address rather than relying on this page.
1. Accepting these terms
You accept them by creating an account or by using the service. If you are doing that for a company, you are saying you are allowed to bind it. The privacy notice, the data processing agreement, and the subprocessor list are part of this agreement.
2. What the service is right now
Comment is in early access. Accounts are created by invitation, not by open signup, and the feature set on the pricing section is what exists today. Parts of the product are marked "planned" or "not built" there on purpose; nothing on this site is a commitment to ship a feature by a date.
There is no charge during early access. If we start charging, you will be told before it affects your account and you will have to agree to it — we will not convert a free account into a paid one by silence.
3. Your account
- Keep your credentials to yourself; you are responsible for what your account does.
- One human per login. Invite your teammates properly instead of sharing an account — invitations are part of the product.
- Tell us promptly if you think someone else has got in.
4. Installing Comment on a website
This is the part that matters most, because our code runs on your pages.
- Only install it on sites you own or are authorised to change. Each environment is limited to the origins you configure, and you must not try to make it run anywhere else.
- You are the controller of the reports your visitors send. You are responsible for telling them what you collect and for having a lawful basis to do it. Our privacy notice describes the mechanics so you can describe them too.
- Do not use Comment to watch people. It is not built for employee monitoring or covert observation, and using it that way is a breach of these terms.
- Do not aim it at sensitive data. Do not deliberately route health, financial, biometric, children's, or other special-category data into reports or session metadata. The product minimises and redacts, but that is not a licence to feed it things it should not hold.
5. Acceptable use
Do not:
- break the law with it, or help someone else do so;
- upload malware, or content you have no right to upload;
- attack the service — scanning, flooding, circumventing rate limits, or trying to reach another customer's data;
- resell it or run it as a service for third parties without our written agreement.
We can suspend an account that is doing any of this, and we will tell you why. Where the problem is not urgent, we will ask you to fix it first.
Unlimited use. When a plan says unlimited, it means there is no fixed cap on normal use by the workspace for its own sites. It does not cover automated or scripted report generation, reselling or sharing the workspace as a service to others, or use that places an unreasonable load on the service compared with typical workspaces on the same plan. If your use falls outside that, we will contact the workspace owner first and work with you to find a plan that fits before limiting anything, unless we need to act sooner to protect the service.
6. Your data stays yours
Reports, markup, captured context, attachments, and everything else your workspace holds belong to you. We hold them to run the service for you, and for nothing else. Specifically:
- We do not sell your data or your visitors' data.
- We do not use your reports to train any model of ours.
- We send nothing to an AI provider unless an admin of your workspace turns that on and chooses the provider.
- You can export a workspace at any time, and you can have data erased — see the privacy notice.
7. Our side
The software, the site, the brand, and the documentation are ours. You get the right to use the service while this agreement is in force; nothing here transfers ownership of it.
If you send us feedback about Comment itself, we may act on it without owing you anything. That is the only thing in this section that works in our favour, and it is limited to suggestions about our own product.
8. Availability, and what we do not promise
There is no uptime commitment during early access, and no service credits. The service is provided as it is, without warranties of any kind — merchantability, fitness for a particular purpose, and non-infringement included. We do not promise that Comment finds your bugs, reproduces them, or that any automated check is correct. A person on your team decides whether something is fixed; the product is built that way deliberately.
We may change, interrupt, or discontinue parts of the service. If we are going to shut something down that holds your data, we will give you reasonable notice and a way to export it first.
9. Limitation of liability
Neither of us is liable to the other for indirect, incidental, special, or consequential damages, or for lost profits, revenue, or data, however caused.
Our total liability arising out of this agreement is limited to the greater of the fees you paid us in the twelve months before the claim and US$100. Nothing here excludes liability that cannot lawfully be excluded — including, where it applies to you, liability for death or personal injury, fraud, or breaches of data-protection law that the law says must sit with us. If you are a consumer, your statutory rights are unaffected.
10. Ending it
You can stop at any time: remove the script tag and ask us to close the account. We can end an early-access account with reasonable notice, or immediately if it is being used in a way that breaches section 4 or 5.
When the account ends, you have 30 days to export what you have. After that we delete it, and copies in backups age out on the backup cycle.
11. Changes to these terms
We will post changes here with a new date. For anything that materially affects you, we will email the workspace admin before it takes effect. Carrying on using the service after that is acceptance; if you would rather not, close the account and export your data.
12. Getting in touch
privacy@commentunderscore.com for anything about these terms, the DPA, or your data. security@commentunderscore.com for anything that looks like a vulnerability.