On a separate note, if this is a real product, you might need to pay particular attention to data processing agreements etc., as the current T&Cs and Privacy Policy are actually missing how you process the input data, what you use, how long/where you store it, etc.
> All comments are processed and completely forgotten.
This is secure in terms of privacy but not safe in terms of operations, because if it gets even a little scale, your demo will soon enough be used to fine-tune spam comments for free.
On a separate note, if this is a real product, you might need to pay particular attention to data processing agreements etc., as the current T&Cs and Privacy Policy are actually missing how you process the input data, what you use, how long/where you store it, etc.