Effective September 20, 2026 · Version 1.2
This Privacy Policy describes how Caleb Alan Mahan, operating the Commz service ("Commz," "we," "us," or "our"), collects, uses, and shares information when you use commz.net, app.commz.net, the Commz desktop app, the Commz Bot API, and related services (together, the "Service"). We do not sell your personal data, we do not show ads, and we collect only what the Service needs to work.
1. Information We Collect
1.1 Information you provide
- Account information: email address, username, display name, password (held by our sign-in provider, never by us), and date of birth (required for age verification)
- Phone number (optional): if you choose to add a United States phone number for verification codes, text-message two-factor authentication, or account recovery. We also record when you consented to receive text messages and which version of the consent wording you saw
- Two-factor authentication: when you enroll an authenticator app, the shared secret is created and stored by our sign-in provider (AWS Cognito). We never see the codes your app generates. We store which methods you have enabled
- Profile information: profile photo, banner, bio, status, interests, and badges
- Content: messages, files and attachments, voice, video, and screen-share streams, images, clips, polls, and other content you share
- Payment information: when you subscribe, tip, or receive payouts, payment details are handled directly by Stripe. We receive only limited transaction metadata (amount, date, status, payment method type), never your card number or bank details
- Bots you create: bot name, description, permissions, and the tokens issued to it
- Communications and reports: support requests, bug reports you send from Settings, and reports you file about content or users
1.2 Information collected automatically
- Log data: IP address, browser type, operating system, referring URLs, pages visited, and timestamps
- Signed-in devices: for each active session, a device description derived from your browser or app, the time it was last active, and the session identifier, so you can review and sign out other devices
- Usage data: features used, communities joined, content viewed, and streaming activity
- Crash and error reports: if the app hits an error, a redacted report (error message, app version, screen) may be sent to us. Access tokens and other credentials are removed before it leaves your device
- Preferences and local storage: app and notification preferences may be stored with your account so they sync across devices. Device-specific choices, last-visited channels, unread indicators, drafts, and sign-in state are stored in your browser or app storage on your device
1.3 Information from third parties
- AWS Cognito: sign-in tokens, session state, two-factor enrollment status, and whether your email and phone are verified
- Stripe: subscription status, payment history metadata, and connected-account (payout) status
2. How We Use Your Information
We use the information we collect to:
- Provide, maintain, secure, and improve the Service
- Verify your age and enforce age restrictions on adult content
- Send verification codes, one-time passcodes, and account recovery codes by email or, with your consent, by text message
- Process payments, subscriptions, tips, and payouts through Stripe
- Enable communication between users (messaging, streaming, voice, and video)
- Scan uploaded files for malware before other users can download them
- Enforce our Terms of Service and content policies, and respond to reports
- Respond to your support requests and bug reports
- Send service-related notifications (account security, policy updates)
- Detect and prevent fraud, abuse, and security incidents
- Comply with legal obligations
- Analyze aggregated, anonymized usage patterns to improve the platform
We do not sell your personal data. We do not use your data for targeted advertising. Commz is ad-free.
3. How We Share Your Information
3.1 Service providers
We share data with the following providers, who process it on our behalf:
- Amazon Web Services (AWS): cloud infrastructure, database storage (DynamoDB), file storage (S3), sign-in and two-factor authentication (Cognito), live video streaming (IVS), email delivery (Amazon SES), text-message delivery (AWS End User Messaging SMS), and malware scanning of uploaded files (Amazon GuardDuty). Data is stored in the US East (N. Virginia) region by default. AWS Privacy Notice: aws.amazon.com/privacy
- Stripe, Inc.: payment processing for plans, tips, creator subscriptions, and creator payouts, under Stripe's Privacy Policy: stripe.com/privacy
- LiveKit: real-time voice, video, and screen sharing in voice rooms. Commz may operate LiveKit on infrastructure it controls
- GitHub: the desktop app downloads installers and updates from GitHub releases; GitHub receives your IP address when it does
3.2 Text messages and phone numbers
Phone numbers and text-message consent are used only to send the security messages described in our SMS Messaging Terms. Mobile phone numbers and SMS consent will not be shared with third parties or affiliates for marketing or promotional purposes. Text-messaging opt-in data and consent are not sold or shared with any third party. Our delivery provider (AWS End User Messaging SMS) receives your number only to deliver a message you requested.
3.3 Other users
The following is visible to other users: your username, display name, profile photo, banner, bio, status, badges, public communities you have joined, and content you post in communities or send to other users. Community owners and moderators can see reports and moderation records for their community. Bots installed in a community can receive the content and events their permissions allow.
3.4 Legal requirements
We may disclose your information when required by law, court order, or government authority, or when we believe disclosure is necessary to protect our rights, prevent fraud, or respond to an emergency involving a threat to safety. We comply with valid legal process, including DMCA notices and subpoenas, and we report child sexual abuse material to NCMEC.
3.5 Business transfers
If Commz is acquired by or merged with another company, your information may be transferred to the acquiring entity. We will notify users by email and/or prominent notice on the Service before any such transfer.
4. Data Retention
- Account data: retained while your account is active and during the 30-day cancellation window after you request deletion. Final deletion runs after that window; verified privacy requests and legal obligations may require a different schedule
- Phone number and SMS consent: your number is removed when you remove it, opt out, or delete your account. We keep a record of consent and opt-out events for as long as needed to demonstrate compliance with messaging laws
- Two-factor authentication: enrollment data is removed when you remove the method or delete your account
- Signed-in devices: session records expire automatically after a period of inactivity or when you sign out
- Messages: your message content is removed during final account deletion, leaving a deleted-account placeholder. Copies retained by other users are outside our control
- Files and media: personal uploads are removed during final deletion. Shared community assets remain with transferred or archived communities. Files blocked by malware scanning are deleted from storage. Moderation evidence and material under a legal retention requirement may be retained separately
- Payment and tip records: limited transaction records may be retained for tax, accounting, dispute, fraud-prevention, or other legal purposes
- Crash reports and logs: kept for a limited time for debugging and security
- Security, moderation, and backup records: retained separately when necessary for security, legal obligations, or recovery. Deleted accounts are not restored to active use from backups
5. Data Security
We implement industry-standard measures to protect your information:
- All data in transit is encrypted using TLS 1.2 or later
- Passwords are never stored by us; sign-in is handled by AWS Cognito using secure hashing
- Optional two-factor authentication with authenticator apps and, where enabled, email or text-message codes
- Payment data never touches our servers; it is processed entirely by Stripe
- AWS infrastructure encrypts stored data at rest
- Uploaded files are stored privately, scanned for malware, and shared only through short-lived links issued to people who can already see the conversation
- The desktop app stores sign-in tokens in encrypted, operating-system-backed storage
- Access to production systems is restricted to authorized personnel
Encrypted direct messages. Optional end-to-end encryption covers new DM text after all participants approve. Attachments, calls, participant identities, timestamps, and other metadata are not covered. Ordinary messages are readable by the Service. Encrypted messages cannot be reported to Commz, because we cannot read them; you can still report the user, block them, or revoke a device. Private keys are encrypted in account-scoped storage on your device using a non-extractable browser key, which does not protect a compromised device. Recovery keys are private backups you must keep safe; losing every device and your backup makes covered messages unrecoverable. This encryption has not been independently audited.
No security system is impenetrable. If a data breach affects your personal information, we will notify you within 72 hours where the GDPR requires it, or as otherwise required by applicable law.
6. Your Rights and Choices
6.1 All users
- Access and correction: view and update your account and profile information in Settings
- Two-factor authentication: add or remove methods in Settings → Security
- Phone number and text messages: remove your phone number or turn off text-message two-factor authentication in Settings → Security, or reply STOP to any Commz text message
- Signed-in devices: review sessions and sign out other devices in Settings → Security
- Deletion: request deletion in Settings → Security. Your account is deactivated immediately, with 30 days to cancel or export data before final deletion. Signing in does not cancel deletion. Communities you own transfer to an eligible member or are archived. Contact us for earlier deletion or another privacy request
- Data export: use Download account data in Settings → Security or on the deletion recovery screen for a JSON export. It includes attachment metadata but not media files or device-only data; end-to-end encrypted content stays encrypted
- Notifications: configurable in Settings → Notifications
Commz is based in Texas and primarily serves the United States. Depending on your state and applicable law, you may also have rights to access, correct, delete, or obtain a copy of your data, or to appeal a privacy-request decision. Contact support@commz.net; the in-app recovery window does not replace legal response deadlines.
6.2 California residents (CCPA)
California residents have the right to know what personal information we collect and how it is used, to delete personal information (subject to exceptions), to opt out of the sale of personal information (we do not sell it), and to non-discrimination for exercising these rights. Email support@commz.net with the subject "CCPA Request."
6.3 European users (GDPR)
If you are in the European Economic Area, the UK, or Switzerland, we process your data on the basis of contract performance (providing the Service), legitimate interests (fraud prevention and security), legal compliance, and consent where required (for example, text messages). You have the right to access, rectify, and erase your data; to restrict processing and data portability; to object to processing based on legitimate interests; to withdraw consent; and to lodge a complaint with your local data protection authority. To exercise these rights, contact support@commz.net.
Data transfers: your data is stored on AWS servers in the United States. Transfers from the EU to the US rely on Standard Contractual Clauses with AWS; a copy is available on request.
7. Children's Privacy (COPPA)
Commz is not directed to children under 13 and we do not knowingly collect personal information from them. We collect date of birth at registration to enforce this. If we learn that we have collected personal information from a child under 13, we will delete it and terminate the account. If you believe a child under 13 has an account, contact support@commz.net.
8. Cookies and Local Storage
Commz uses account settings and browser or app storage, not third-party cookies, to remember preferences and sign-in state. This includes display and notification preferences (which may sync with your account), device-specific audio and desktop choices, last-visited channels and communities, unread state, drafts, community ordering, and the sign-in tokens that keep you signed in on that device. Sign-in state is necessary for the Service to function while you use Commz.
We do not use advertising cookies, analytics cookies, or third-party tracking cookies.
9. Changes to This Policy
We may update this Privacy Policy to reflect changes in our practices or applicable law. We will notify you of material changes by posting the updated Policy at commz.net/legal/privacy and in the app, and by updating the effective date and version above. Where required by law, we will provide 30 days' notice before material changes take effect.
10. Contact Us
For privacy inquiries, data requests, or concerns:
Caleb Alan Mahan · 4510 Terry O Ln Unit 228, Austin, TX 78745 · support@commz.net
Response time: within 30 days (or 72 hours for breach notifications).