CometReplyAI

Security & Privacy

CometReplyAI handles sensitive communications, so it is designed with security as a core principle: least-privilege platform access, encrypted token storage, per-user data isolation, and review-before-send workflows.

Per-user data isolation

Every table is protected by PostgreSQL row-level security scoped to your account. Access is enforced in the database itself, not just in application code, so one account can never read another account's messages, drafts, or settings.

Encryption in transit and at rest

All traffic to CometReplyAI runs over HTTPS. The access tokens that connect your inboxes and calendars are encrypted before they are written to the database, so a raw token is never stored in plain text.

No data monetization

Your messages are used only to power the features you turn on — drafting and organizing your replies. We do not sell your data, we do not share it with advertisers, and it is never used to train AI models.

AI processing, scoped to your request

Generating a draft means the relevant message content is sent to our AI provider to produce that reply. It is processed to complete your request under provider terms that prohibit training on it — not analyzed to build a profile of you.

Minimal logging — never message contents

We never write the body of your emails or messages to our application logs. Operational diagnostics record what happened (timings, error codes, account identifiers) — not what you wrote.

Review before send, and full control

AI drafts replies; you stay in control. Nothing is sent on your behalf until you have read and approved it. You can disconnect any connected account at any time, which revokes CometReplyAI's access to it.

Account protection

New passwords are checked against known-breached-password databases at sign-up, so a credential exposed in a past breach can't be reused here. Connected platforms grant only the scopes a feature needs.

Payments

Checkout and billing run on Stripe's hosted, PCI-compliant infrastructure. Your card details are handled by Stripe and never touch CometReplyAI's servers.

Reporting a vulnerability

Found a security issue? We want to hear about it. Please report it through our contact page with enough detail to reproduce it, and give us a reasonable window to respond before any public disclosure.

For how we collect and handle data, see our Privacy Policy.