sayy
how it works features pricing docs Request access →
— Legal

Privacy Policy

// Effective: April 22, 2026 · Last updated: April 22, 2026

Overview Information We Collect How We Use Data Cookies & Analytics Third-Party Services Data Storage Your Rights Children's Privacy Policy Changes Contact Us

Overview

Sayy ("we," "our," or "us") operates the Sayy commenting platform, including the website at sayy.io, the embeddable comment widget, the REST API, and the WordPress plugin. This Privacy Policy describes how we collect, use, and protect information when you use our services.

Sayy is built privacy-first. Our Tier 1 spam filter makes zero external requests. We never serve ads, never sell data, and never fingerprint readers.

By using Sayy, you agree to the collection and use of information as described in this policy. If you do not agree, please do not use our services.

Information We Collect

Account Information

When you create a Sayy account (as a site owner or team member), we collect:

  • Email address
  • Display name
  • Password (hashed and salted — never stored in plain text)
  • Organization or website URL

Comment Data

When a reader posts a comment through the Sayy widget, we collect:

  • Comment text and any text anchors (highlighted passages)
  • Display name (or guest identifier)
  • Timestamp and page URL
  • Votes and reactions

Technical Data

We automatically collect limited technical data necessary to operate the service:

  • IP address (used for rate limiting and spam detection — not stored long-term)
  • Browser type and version (via User-Agent header)
  • Referring page URL

We do not collect or use browser fingerprints, device IDs, or any cross-site tracking identifiers. The boot.js script is fingerprint-free by design.

How We Use Your Data

We use collected information for the following purposes:

  • Operating and delivering the Sayy commenting service
  • Detecting and preventing spam, abuse, and fraudulent activity
  • Processing AI moderation requests (Tier 2 — only when configured by the site owner with their own API key)
  • Providing analytics and engagement metrics to site owners
  • Sending transactional emails (account verification, password resets, billing)
  • Improving the service based on aggregate, anonymized usage patterns

We do not use your data for advertising, profiling, or selling to third parties. Ever.

Cookies & Analytics

Cookies We Set

Sayy uses a minimal set of cookies necessary to operate the service:

  • Session cookie — Authenticates logged-in site owners and team members in the Sayy dashboard. Expires when you close the browser or after 30 days.
  • Preference cookie — Stores widget display preferences (e.g., collapsed/expanded state). First-party only. No personal data.

The embeddable widget (boot.js) does not set any cookies for readers in its default (Tier 1) configuration.

Analytics

We use privacy-respecting, first-party analytics to understand how the Sayy dashboard and website are used. We collect aggregate metrics such as page views, feature usage, and session duration. We do not use Google Analytics or any third-party tracker that profiles users across websites.

Managing Cookies

You can control cookies through your browser settings. Disabling cookies may affect your ability to use the Sayy dashboard but will not impact the reader-facing comment widget.

Third-Party Services

We share data with third parties only as necessary to operate the service:

  • Cloud hosting — Our infrastructure runs on industry-standard cloud providers with SOC 2 compliance.
  • Payment processing — Billing is handled by Stripe. We never store your credit card details directly.
  • AI moderation (Tier 2 only) — When a site owner configures AI moderation with their own API key (OpenAI or Anthropic), comment text is sent to the chosen provider for spam scoring. This is strictly opt-in and uses the site owner's credentials — Sayy does not proxy these requests through our systems.
  • Transactional email — We use an email delivery service for account-related emails only.

We do not sell, rent, or trade personal data to any third party.

Data Storage & Security

Comment data is stored in encrypted databases with access restricted to authorized services. We implement industry-standard security measures including encryption in transit (TLS 1.3), encryption at rest, and regular security audits.

Data retention periods depend on your plan tier:

  • Free — 7-day analytics retention; comments stored indefinitely
  • Pro — 90-day analytics retention
  • Business — 365-day analytics retention
  • Agency — 730-day analytics retention

When a site owner deletes their account, all associated data (comments, configuration, analytics) is permanently purged within 30 days.

Your Rights

Depending on your jurisdiction, you may have the following rights regarding your personal data:

  • Access — Request a copy of the personal data we hold about you
  • Correction — Request that we correct inaccurate or incomplete data
  • Deletion — Request that we delete your personal data
  • Portability — Request your data in a structured, machine-readable format (JSON or CSV)
  • Objection — Object to the processing of your data in certain circumstances
  • Withdraw consent — Where processing is based on consent, withdraw that consent at any time

Site owners can export all comment data (including author information, threads, and votes) at any time via the Sayy dashboard or REST API. To exercise your rights as an individual commenter, contact us at the address below.

Children's Privacy

Sayy is not directed at children under the age of 13 (or the applicable age of consent in your jurisdiction). We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, please contact us and we will promptly delete it.

Policy Changes

We may update this Privacy Policy from time to time. When we make material changes, we will notify registered users via email and update the "Last updated" date at the top of this page. Continued use of Sayy after a change constitutes acceptance of the updated policy.

Contact Us

If you have questions about this Privacy Policy or wish to exercise your data rights, contact us at:

Sayy
Email: privacy@sayy.io

Home Privacy Policy Terms & Conditions
© 2026 Sayy. All rights reserved.