FlowConsent
ServicesHow it worksPricingBlogDocumentation
ServicesHow it worksPricingBlogDocumentationLog inTry FlowConsent
Log inTry FlowConsent
FlowConsent

GDPR-compliant consent, EU-hosted, live in under ten minutes — without a cookie wall.

EU-HOSTED·RGPD·SOC 2
Product
  • Services
  • How it works
  • Pricing
  • Extension
Company
  • Blog
  • Documentation
  • Solutions
  • FlowConsent App
Legal
  • Privacy Policy
  • Terms of Service
  • Legal notice
  • Cookies
© 2026 FlowConsent by BeBranded. All rights reserved.
FrancaisDeutschEspanol
All systems operational

Does your website use third-party services? Get GDPR compliant in minutes.

Try FlowConsent
  1. Home
  2. Services
  3. Social Media
  4. Commento

Commento

MarketingWebsite

Related services

A

AddShoppers

AddShoppers is a digital marketing technology that helps businesses reach, engage, and convert their target audience online. It provides advanced targeting, campaign management, and performance analytics capabilities. AddShoppers enables marketers to deliver personalized experiences across channels, optimize campaign ROI, and gain actionable insights into customer behavior. With automation features and data-driven optimization, AddShoppers empowers marketing teams to achieve measurable growth.

Marketing

AddThis

AddThis is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. AddThis integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, AddThis helps organizations maintain robust websites that meet user expectations and technical requirements.

Marketing

AddToAny

AddToAny is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. AddToAny integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, AddToAny helps organizations maintain robust websites that meet user expectations and technical requirements.

Marketing

Cackle

Cackle is a foundational web service that powers critical website functions and digital experiences. It provides reliable infrastructure, seamless integration capabilities, and consistent performance across all devices and browsers. Cackle supports modern development practices and scales with growing business needs. With a focus on stability and compatibility, Cackle ensures your website delivers a smooth, uninterrupted experience to every visitor and search engine crawler.

Marketing

Douban

Douban is a versatile web technology that supports digital platforms with specialized functionality and enhanced capabilities. It provides robust tools and services that integrate with modern websites and applications seamlessly. Douban is designed to improve operational efficiency, user experience, and digital performance. Trusted by developers and businesses alike, Douban offers reliable solutions that scale with organizational needs and evolving web standards.

Marketing

EmbedSocial

EmbedSocial is a web technology service that provides essential functionality for websites and digital platforms. It delivers core capabilities that support site operations, content delivery, and user experience optimization. EmbedSocial integrates seamlessly with modern web architectures, ensuring reliable performance and compatibility across browsers and devices. Trusted by businesses worldwide, EmbedSocial helps organizations maintain robust websites that meet user expectations and technical requirements.

Marketing
Get compliant — Try FlowConsent free

Free plan · 10-min setup

What does Commento do?

Commento is a lightweight, privacy-focused comment widget designed as a minimal alternative to Disqus. It has no advertising, no cross-site tracking, and sets only a small session or authentication cookie when users log in to comment. When self-hosted, it presents very low privacy risk; when using the hosted commento.io service, a third-party disclosure is advisable. Consent is generally not required for the essential session cookie, but operators should document its use in their privacy notice.

What Is Commento and How Does It Work

Commento is an open-source, privacy-focused comment widget built as a lightweight and ethical alternative to advertising-heavy comment platforms such as Disqus. It can be deployed in two ways: self-hosted on the operator''s own server infrastructure (giving complete control over data), or via the commento.io hosted service. The widget is embedded in a webpage via a small JavaScript snippet loaded from cdn.commento.io (for hosted deployments) or from the operator''s own domain (for self-hosted deployments). Commento has no advertising network, does not build cross-site user profiles, and does not sell or share comment data with third parties.

When a visitor wishes to leave a comment, they can do so as a guest (providing a name and email) or by logging in via Commento''s own account system or supported OAuth providers (such as Google or GitHub, if configured). The commenting experience is minimal by design: no sidebar widgets, no recommended content, no behavioural targeting, and no data monetisation.

Data and Cookies Collected

Commento''s data footprint is intentionally minimal. It collects only: the commenter''s name and email address (for logged-in users or when provided as a guest); the comment content itself; the page URL where the comment was posted; and a timestamp. A session or authentication cookie is set when a user logs in to the comment system. This cookie is used solely to maintain the logged-in state during the session and is not used for tracking, advertising, or cross-site identification. It expires at the end of the browsing session or after a short fixed duration. No analytics cookies, advertising identifiers, or persistent tracking identifiers are set by Commento itself.

GDPR and ePrivacy Implications

Under the ePrivacy Directive, cookies that are strictly necessary for a service explicitly requested by the user are exempt from the consent requirement. Commento''s session and authentication cookies fall into this category: a user who clicks to leave a comment has explicitly requested the comment functionality, and the session cookie is essential for that functionality to work. No prior consent is therefore required for the Commento session cookie under ePrivacy rules. Under GDPR, the processing of comment author data (name, email, comment content) can rely on legitimate interest (Art. 6(1)(f)) for comment moderation and spam prevention, or on the performance of a contract/service if the user has accepted terms of service for the comment platform.

Get GDPR compliant in 10 minutes

Free plan available · No credit card required

Try FlowConsent free

Self-Hosted vs Hosted Service

The privacy risk profile differs significantly between self-hosted and hosted deployments. When self-hosted, all comment data (names, emails, comment text) is stored on the operator''s own server. There is no third-party involvement, no international data transfer, and the operator has full control. When using the hosted commento.io service, comment data is processed by a third-party provider. Operators should disclose this in their Privacy Policy and include the commento.io domains in their cookie notice. Note that the commento.io hosted service was wound down by its original developers; operators considering Commento should evaluate actively maintained self-hosted forks such as Commento++ or Commentoplusplus.

Disclosures and Privacy Notice Requirements

Even though consent is not required for the essential session cookie, operators must inform users of the processing in their Privacy Policy. The policy should explain: that Commento is used for the comment functionality; what data is collected from commenters (name, email, comment text); how long comment data is retained; whether the hosted service or a self-hosted solution is used; and how users can request deletion of their comments or account data. If OAuth login is enabled, the relevant third-party providers (Google, GitHub, etc.) should also be mentioned.

Practical Compliance Steps for Operators

For a compliant Commento deployment: prefer self-hosting to avoid third-party data transfers; document comment data processing in your Records of Processing Activities with legitimate interest as the legal basis; update your Privacy Policy to describe the comment widget, data collected, and retention periods; list the Commento session cookie in your cookie notice as strictly necessary (exempt from consent); if using hosted commento.io or a fork, include the provider domains in your Privacy Policy; provide commenters with a way to request deletion of their comment data or account; and if you enable OAuth login, ensure the relevant third-party login providers are covered in your policy.

GDPR consent category

Marketing

Websites using Commento must obtain user consent under GDPR regulations.

Legal basisFor self-hosted Commento, the session and authentication cookies are strictly necessary for the comment functionality explicitly requested by the user (logging in to comment), and can rely on the strictly necessary exemption under ePrivacy rules without requiring consent. The legal basis for processing comment author data is legitimate interest (Art. 6(1)(f) GDPR) or contract/service delivery. For hosted commento.io, a disclosure in the Privacy Policy and cookie notice is advisable as the widget involves a third-party service; consent or at minimum a clear disclosure is recommended.
Risk levellow
Applicable regulationsGDPR, ePrivacy Directive

DPIA considerations

A formal DPIA is not required for standard Commento deployments given its minimal data collection profile and low risk classification. Commento does not set advertising or tracking cookies, does not share data with third parties for profiling, and does not create cross-site user profiles. The session and authentication cookies are strictly necessary for the comment functionality. Operators should nonetheless document the processing of comment author data (typically a name and email address for comment moderation) in their Records of Processing Activities, and ensure that comment authors are informed of this processing in the Privacy Policy. For self-hosted deployments, the data never leaves the operator's own infrastructure. If the hosted service is used and user data is transferred internationally, a brief proportionality review is sufficient rather than a full DPIA.

Sample consent text

This website uses the Commento comment widget to enable reader discussion. Commento uses a small session cookie to keep you logged in while you comment. This cookie is strictly necessary for the comment feature to work and does not track you across other websites. No consent is required for this cookie, but you can disable commenting entirely by not engaging with the comment widget.

Technical details

Tracking methodLightweight JavaScript embed; session and authentication cookies only; no advertising tracking or cross-site data sharing; open-source codebase auditable by operators
Server locationVaries: self-hosted (operator's own infrastructure) or hosted via commento.io (location depends on provider; commento.io was US-based before service wind-down)
Data transferred outside the EUOnly applicable when using the hosted commento.io service, which was US-based. When self-hosted, all data remains on the operator's own infrastructure with no third-country transfer. Operators using any hosted successor or fork should verify the data residency of that specific provider.

Third-party domains contacted

commento.iocdn.commento.io

Cookies placed

NameTypeDurationPurpose
commento_sessionsessionSessionStrictly necessary session cookie that maintains the authenticated state of a logged-in commenter during their browsing session. Not used for tracking or advertising.
commento_tokenpersistent30 daysAuthentication token cookie used to keep a commenter logged into their Commento account across sessions if they select the stay logged in option. Strictly necessary for the requested authentication functionality.

Commento places tracking cookies for advertising — comply with GDPR using FlowConsent.

Get started freeScan your site

Frequently asked questions

What cookies does Commento set?

Commento sets a minimal number of cookies. The primary cookie is a session or authentication cookie that is created when a user logs into the comment widget. This cookie is used solely to keep the user authenticated during their visit and is not used for tracking, advertising, or cross-site identification. It expires at the end of the browsing session or after a short fixed period. Commento does not set analytics cookies, advertising identifiers, or any tracking cookies. When self-hosted, there are no third-party cookies at all.

Is consent required before loading Commento?

For the essential session and authentication cookies set by Commento, consent is generally not required under the ePrivacy Directive, as these cookies are strictly necessary for the comment functionality that the user has explicitly requested by interacting with the comment widget. However, if using the hosted commento.io service, the widget involves a third-party connection, and a clear disclosure in your privacy notice and cookie policy is required. If OAuth login is enabled, additional third-party cookies from the OAuth provider may require consent.

What is the legal basis for processing comment data through Commento?

The legal basis for processing comment author data (name, email address, comment content) through Commento is typically legitimate interest under GDPR Article 6(1)(f), specifically the interest in enabling reader discussion and moderating comments. If users sign up for a Commento account, contract performance (Article 6(1)(b)) may also apply. The strictly necessary session cookie does not require a GDPR legal basis as it is covered by the ePrivacy strictly necessary exemption, but the underlying data processing of comment content still requires a documented basis.

Does Commento transfer data to the United States or other third countries?

When Commento is self-hosted on the operator's own server, no data is transferred to any third country. All comment data remains on the operator's chosen infrastructure. When using the hosted commento.io service, data was processed by the commento.io provider, which was US-based. Note that the original commento.io hosted service has been wound down. If using a hosted fork or successor, operators must verify where that provider processes data and document the transfer mechanism accordingly.

Do I need a DPIA before deploying Commento?

A formal DPIA is not required for standard Commento deployments. Commento collects minimal data, does not profile users across sites, does not involve advertising networks, and has no high-risk processing characteristics that would trigger the mandatory DPIA requirement under GDPR Article 35. Operators should nonetheless document the processing of commenter data (name, email, comment content) in their Records of Processing Activities. If OAuth login is enabled and involves additional third-party data flows, those should be assessed separately.

How do I implement Commento in a GDPR-compliant way?

Self-host Commento on your own infrastructure to avoid any third-party data transfers. Document the processing of comment author data in your Records of Processing Activities using legitimate interest as the legal basis. Update your Privacy Policy to describe the comment widget, what data commenters provide, retention periods, and how users can request deletion of comments. List the Commento session cookie in your cookie notice as strictly necessary. Provide commenters with contact information for deletion requests. If you enable OAuth login, ensure the relevant third-party providers are named in your Privacy Policy.

What are the alternatives to Commento for privacy-friendly comments?

Other privacy-focused comment alternatives include Isso (open-source, self-hosted, Python-based), Remark42 (open-source, Go-based, with strong privacy controls), and Giscus (GitHub Discussions-based, open-source). All of these can be self-hosted with full data control. For static sites, embedding a simple email-based comment form or a manual moderation system can eliminate any third-party dependency entirely. Choosing a self-hosted solution ensures all comment data remains under the operator's direct control.

How do I update my cookie and privacy policy to include Commento?

Add an entry for the Commento session cookie in your cookie policy table, listing it as a strictly necessary functional cookie with a short duration and describing its purpose as maintaining login state for the comment widget. In your Privacy Policy, add a section describing Commento as the comment provider, what data is collected from commenters (name, email, comment text), how long it is retained, and how users can request deletion. If using a hosted Commento service, name the provider and its location. Update your policy whenever you change your Commento configuration (e.g., enabling OAuth login or switching to a different hosted provider).