Privacy Policy

Last updated 16 August 2026

Comrat is a customer-messaging tool. A business connects its own messaging accounts, and Comrat brings the conversations from those accounts into one inbox so the business can read and reply to them. This policy explains what data passes through Comrat, why, and how to get it removed.

Who this policy is about

Comrat has two kinds of people in it. The business is our customer: they sign in and connect their accounts. The end customer is someone who messages that business on Instagram or another connected channel. We process the end customer's messages on behalf of the business, not for our own purposes.

What we collect

From the business: the email address used to contact them, and an access token issued by the platform they connected. The token is what lets Comrat read and send messages for that account. We never receive or store the password to any connected account.

From connected messaging accounts: the content of messages sent to the business, the sender's platform-assigned account identifier, their username or display name where the platform provides it, and the time each message was sent.

We do not collect payment details, government identifiers, precise location, or contacts. We do not buy data about you from third parties, and we do not sell or rent any data to anyone.

Why we collect it

Only to operate the product: to show the business its conversations, to let it reply, to keep an account connected without asking the business to re-authorise every hour, and to prevent the same message appearing twice. We do not use message content for advertising or profiling, and we do not use it to train machine-learning models.

Where it is stored

Data is held in a Postgres database hosted by Supabase in the European Union (Frankfurt), and the application runs on Vercel. Access tokens are stored in a table that is unreadable by the application's public client and reachable only by the server.

Who we share it with

Our infrastructure providers — Supabase and Vercel — process data on our behalf in order to host it. The messaging platform a business connects, such as Meta, necessarily sees the messages sent through it. Beyond that, we share nothing. We will disclose data if the law compels us to, and will tell the affected business unless we are prohibited from doing so.

How long we keep it

Conversations remain until the business deletes them or closes its account. Access tokens are deleted as soon as a channel is disconnected. When an account is closed we delete its data within 30 days, except where we are required to retain something longer by law.

Your rights

You can ask us for a copy of the data we hold about you, ask us to correct it, or ask us to delete it. Businesses can disconnect a channel at any time from the app's settings, which revokes our access immediately. If you are an end customer, you can also revoke Comrat's access from within the messaging platform you used.

To make any request, email enisleader@gmail.com. We answer within 30 days.

Children

Comrat is a business tool and is not directed at children. We do not knowingly collect data from anyone under 16. If you believe we have, contact us and we will delete it.

Changes

If this policy changes materially we will update the date at the top and notify connected businesses by email before the change takes effect.

Contact

Questions about this policy or how your data is handled: enisleader@gmail.com.