Skip to content
Agent Pricing Docs Blog
GitHub Get started
  • Terms of Service
  • Privacy Policy
  • Security
  • Data Use Policy

This page is available in English only.

Security

This page explains how we protect your data.


Your content is not used to train AI

We want to be clear about this:

  • We do not use your files, conversations, or prompts to train our own or third-party general-purpose AI models, unless your organization expressly asks for a separate training or fine-tuning workflow and agrees to terms that govern it.
  • We do not sell your personal data, and we do not share it for advertising. We share data only with the service providers that help us run the Services, as listed in our Data Use Policy, or with services you choose to connect.

How we protect your account

  • No passwords — Comma uses passwordless authentication. You sign in with your email and a verification code. No passwords to steal or leak.
  • Secure token storage — Your session is encrypted with a key kept in the macOS Keychain.
  • Third-party connections — When you connect services like Slack, GitHub, or Google, Comma uses standard OAuth with scoped permissions. You can revoke access at any time. Agents never see your raw login credentials.

Telemetry and analytics

Comma collects basic usage data to help us improve the product, such as how features are used.

What telemetry does not include:

  • Your file contents
  • Your prompts or conversations
  • Any content from your connected services

To debug issues and keep the Services reliable and safe, we may also use limited signals derived from content, as described in our Data Use Policy.

All telemetry is transmitted over encrypted connections. We are working on providing an opt-out option for users who prefer to disable telemetry entirely.


Vulnerability reporting

If you discover a security vulnerability in Comma, please let us know:

Email: support@comma.surf

We acknowledge reports within 48 hours and provide an initial assessment within 5 business days. We work with reporters to resolve issues before public disclosure.


Compliance

  • GDPR / UK GDPR — Our Privacy Policy addresses EU and UK data protection requirements.
  • CCPA / CPRA — California-specific disclosures are included in our Privacy Policy.

For details, see our Privacy Policy.


Questions?

For security questions, contact us at support@comma.surf.

For privacy inquiries, email support@comma.surf or see our Privacy Policy.

Product

  • Features
  • Agent
  • Pricing
  • Download
  • Documents
  • Blog
  • FAQs

Legal

  • Terms of Service
  • Privacy Policy
  • Security
  • Data Use Policy

Connect

  • Contact us
  • X (Twitter)
  • GitHub

© 2026 AFK AI, Inc.

Theme
English简体中文Simplified Chinese日本語Japanese한국어KoreanEspañolSpanishFrançaisFrenchDeutschGermanPortuguêsBrazilian Portugueseहिन्दीHindi