KomeninKomenin

Privacy Policy

How Komenin collects, uses, and protects your data.

Last updated: 2 September 2026

1. What we collect

  • Account data: name, email, and sign-in identifiers (Google, email OTP, or SSO).
  • Workspace configuration: connected social accounts, proxies, providers, and settings you create.
  • Operational content: drafts, comments, campaigns, approvals, and activity generated through the Service.
  • Credentials you provide (BYOK API keys, session tokens) — stored encrypted.
  • Usage and billing records: plan, orders, AI credit consumption (model and token counts, not your prompts).
  • Technical data: logs, IP address, and device/browser information needed to operate and secure the Service.

2. How we use it

  • Provide and operate the Service (drafting, scheduling, publishing, analytics).
  • Process payments and fulfill entitlements via our payment processor.
  • Secure the platform, prevent abuse, and enforce quotas and rate limits.
  • Communicate with you about your account, quota thresholds, and important changes.
  • Improve reliability and features (in aggregate, not by reading your private content).

3. AI processing and your prompts

When you use AI features, the text needed to generate a result is sent to the AI provider you configured (your own key, or our gateway for Komenin AI) solely to produce that result.

We record metering metadata — the model used and token counts — for billing and analytics. We do not use your prompts or generated content to train models, and we do not sell your content.

4. Third-party processors

We use subprocessors to deliver the Service, including: Midtrans (payments), Brevo (transactional email), our hosting/database provider, and the AI provider you select. Each processes data only as needed to provide its service to us.

Connected social platforms (Instagram, Threads, TikTok) receive the content you choose to publish through them, under their own terms and privacy policies.

5. Retention, security, and your rights

  • We retain workspace data while your account is active and delete or anonymize it within a reasonable period after closure, except where law requires longer retention.
  • We apply encryption in transit and at rest, per-workspace isolation, and access controls.
  • You may request access, correction, export, or deletion of your personal data via the contact page.
  • You can disconnect social accounts and remove stored credentials at any time in Settings.

6. Changes and contact

We may update this Policy; material changes will be notified in-app or by email before taking effect.

For privacy questions or data requests, use the contact page.