YouTube Comment Moderation Service
Privacy Policy
This Policy provides the information required by Article 9 of the Brazilian General Data Protection Law (Lei no 13.709/2018 — LGPD) in a clear, adequate and ostensible manner, and includes the disclosures required by the YouTube API Services Terms of Service.
1. Who We Are and What This Policy Covers
1.1 Moderaty is a YouTube comment moderation service operated by Advanced Digital Marketing LTDA, a company registered in Brazil, CNPJ 68.425.709/0001-72, registered address Avenida Paulista 777 ANDAR 15 CONJ 15 SALA 3408 SAO PAULO, SP BRASIL (Moderaty, we, us). For the personal data described in this Policy, Moderaty is the data controller under the LGPD.
1.2 This Policy covers personal data of our users (YouTube channel owners and their authorized team members) and of people who contact us, including visitors to our public website when optional audience measurement is enabled. It also explains, for transparency, how comment data flows through the Service — but note that for comment data we act as processor on behalf of the channel owner, who is the controller (Section 3).
1.3 Our Data Protection Officer (Encarregado de Proteção de Dados) is Andrew Philip Weilbacher, reachable at contact@Moderaty.com. The DPO acts with independence and technical autonomy, in accordance with ANPD Resolution CD/ANPD no 18/2024.
1.4 PROVIDING CERTAIN PERSONAL DATA (ACCOUNT AND BILLING INFORMATION) IS A CONDITION FOR USING THE SERVICE, BECAUSE WITHOUT IT WE CANNOT CREATE YOUR ACCOUNT, CONNECT YOUR CHANNEL, OR PROCESS PAYMENTS. WHERE THAT IS THE CASE, THIS FACT IS DISCLOSED HERE WITH PROMINENCE, AS REQUIRED BY ARTICLE 9, §3, OF THE LGPD. YOUR RIGHTS AND HOW TO EXERCISE THEM ARE IN SECTION 10.
2. The Data We Process, and Why
The table below lists each processing activity, the data involved, the specific purpose, the legal basis under the LGPD, and the retention period. We do not sell personal data, we do not use personal data for advertising profiling, and we do not train machine-learning models on personal data.
| Activity and data | Specific purpose | Legal basis (LGPD) | Retention |
|---|---|---|---|
| Account registration: name, e-mail, Google account ID, channel ID(s) | Create and manage your account; connect your YouTube channel via OAuth; deliver the Service | Contract performance (Art. 7, V) | Duration of the account; deleted immediately on account closure, except the consent-acceptance record (Section 7.1) |
| Billing: name, e-mail, billing address, purchase history, tax ID (if provided). Processed by Stripe, Inc. as our payment processor; we never see or store full card numbers | Process payments, issue invoices, prevent chargeback fraud | Contract performance (Art. 7, V); legal obligation (Art. 7, II — tax and accounting records) | Invoices and tax records: 5 years or the period required by Brazilian tax law |
| Service operation: moderation configuration, moderation outcome records (comment ID reference, comment text truncated to 500 characters, the commenter's handle kept for up to 30 days, verdict, action, timestamp — no other author identifiers) | Execute your moderation instructions; show your activity history | Contract performance (Art. 7, V) | Duration of the subscription; deleted immediately on termination |
| Connection and application-access logs: IP, timestamps, session records | Comply with Articles 13 and 15 of the Marco Civil da Internet; security and abuse prevention | Legal obligation (Art. 7, II) | 6 months, segregated and under secrecy, then automatically deleted |
| Support: e-mail address and content of your messages | Respond to your requests; keep a record of our correspondence | Contract performance (Art. 7, V); legitimate interest (Art. 7, IX) | Up to 2 years after the last interaction |
| Contact form: name, e-mail, optional message, and your opt-in consent (the exact checkbox sentence, timestamp, IP, user agent) | Respond to your contact request; verify your e-mail address before forwarding your name, e-mail, and message to our contact inbox and replying | Consent (Art. 7, I) for the opt-in; legitimate interest (Art. 7, IX) to respond | Until the request is resolved; up to 2 years after the last interaction |
| Security and abuse prevention: access patterns, error logs | Protect the Service, detect and prevent fraud and attacks | Legitimate interest (Art. 7, IX) — balancing test documented; you may object (Section 10) | Up to 12 months |
| Service communications: e-mail | Send operational notices (Terms changes, billing, security alerts). Marketing messages only with your opt-in consent, with unsubscribe in every message | Legal obligation / legitimate interest for operational notices; consent (Art. 7, I) for marketing | Until account closure or consent withdrawal |
| Optional public audience measurement: approved public page paths and campaign values, fixed page titles, external referrer origins, and approved marketing clicks. Our self-hosted Umami collector receives the network IP address and browser user agent and derives pseudonymous sessions/visits and approximate geography | Understand public traffic, approved campaign attribution and marketing-link clicks to improve public website information; no account activity, completed signups, payments, channel/comment content or advertising profiling | Proposed legitimate interest (Art. 7, IX), subject to a separate necessity and balancing assessment awaiting completion before activation (Section 9). If that basis is unsuitable, measurement remains disabled pending consent gating | If activated: detailed measurement records limited to 90 days; backup copies expire within 7 days after deletion. Activation requires a verified purge and backup-expiry process; these are operational limits, not statutory LGPD deadlines |
3. Comment Data: We Are the Processor, Not the Controller
3.1 Comments on your channel contain personal data of third parties (the comment authors). For that data, the channel owner is the controller and Moderaty is the operator (processor), under the Data Processing Agreement (DPA) that forms part of our Terms of Service.
3.2 Comment text and author identifiers are retrieved via the YouTube API Services, classified, and acted upon according to the channel owner's configuration. We store the comment text (truncated to 500 characters) together with the moderation outcome record, so your review queue and audit history work. The commenter's public handle is stored with the record in the activity log for up to 30 days and is then erased automatically; you can also erase all stored handles on demand at any time from the log page. Other comment author identifiers (display name and author channel ID) are processed in memory at decision time and never retained — no author channel IDs are kept, and no profiles of comment authors are built or kept. The one exception is identifiers you enter yourself: a blocked-user rule or a protected handle on the rules page stores the identifier you type as your own configuration, matched against incoming comments in memory only. We do not perform author-level behavioral analysis, and we do not train models on comment data.
3.3 Comments may incidentally contain sensitive personal data (for example, hate speech referencing race, religion, or political opinion) and may be authored by minors, whose age we cannot identify. We therefore treat all comment data to the highest protection standard, consistent with the best-interest principle of Article 14 of the LGPD and the ECA Digital (Law no 15.211/2025). The lawful basis for this processing belongs to the channel owner as controller and flows down to us through the DPA.
3.4 If you are a comment author and want to exercise rights over a comment, please contact the channel owner (the controller). If you contact us directly, we will forward your request to the channel owner where possible, within 5 business days. Beyond the commenter's public handle kept in the activity log for up to 30 days (Section 3.2), comment author identifiers are not persistently stored or linked in our database; however, stored comment records include the YouTube comment ID, from which the author could in principle be re-identified via YouTube while the channel owner's access remains active — one more reason your request belongs with the channel owner.
4. YouTube API Services Disclosures
4.1 Moderaty uses YouTube API Services to retrieve comments and execute moderation actions on channels our users authorize. By using the Service, you agree to be bound by the YouTube Terms of Service at https://www.youtube.com/t/terms.
4.2 Information received from YouTube API Services is used only to provide the moderation features described in this Policy, in accordance with the Google Privacy Policy at https://policies.google.com/privacy.
4.3 You can revoke Moderaty's access to your YouTube data at any time via the Google security settings page at https://security.google.com/settings/security/permissions. After revocation, we can no longer access the affected channel; stored commenter handles in the activity log still expire automatically after 30 days (and can be erased on demand at any time), and moderation outcome records (including stored comment text) are handled as described in Section 2.
4.4 YouTube and Google operate under their own privacy policies, which we do not control and for which we are not responsible.
5. Sharing and Recipients
We share personal data only with:
- (a) Infrastructure and service providers acting as our sub-processors or processors under contract, each limited to what it needs to perform its function: Netlify, Inc. (application hosting and delivery — United States); Turso / ChiselStrike, Inc. (database hosting — United States, with edge replicas only in regions we disclose and record); OpenAI, LLC (transient comment classification only, no retention, no model training — United States); Stripe, Inc. (payment processing — United States); and Proton AG (transactional e-mail — contact-form verification, verified contact requests, and service notices, including zero-credit account warnings; recipient e-mail address and message content — Switzerland);
- (b) Google/YouTube, as the platform through which the Service operates and as an independent controller of its own processing;
- (c) Public authorities, courts, or regulators, only when required by law, court order, or to protect our rights, users, or third parties, and always limited to what is legally required; and
- (d) A successor entity in the event of a merger, acquisition, or sale of the Service, subject to this Policy and with prior notice to you.
We do not sell, rent, or trade personal data. An up-to-date list of sub-processors is maintained in the DPA (Annex III), and we give at least 15 days' notice of changes, during which you may object on reasonable data protection grounds.
E-mail submitted to Proton travels over TLS-protected SMTP: message content is not end-to-end encrypted in transit, and a copy of each message we send is retained in our Proton mailbox's Sent folder as the submission record for verification links and notices — kept until account closure or consent withdrawal for service notices, and up to 2 years after the last interaction for contact-form mail (the Section 2 periods for those activities). Proton AG currently processes this e-mail data in Switzerland under its own data processing terms, which permit safeguarded transfers outside Switzerland, the EU, and countries covered by an adequacy decision; transfers from Brazil rely on the ANPD standard contractual clauses described in Section 6.
Optional audience measurement runs in our own Umami instance, separate from the moderation database. Its hosting, proxy/CDN and backup providers may process traffic and infrastructure logs as contracted processors. Their identities, countries, access-log retention and applicable international-transfer mechanisms must be recorded and disclosed before activation; measurement remains disabled until these requirements are complete. No Google advertising or analytics tag is loaded by this integration.
6. International Data Transfers
6.1 Some recipients above are located outside Brazil (including the United States). Transfers of personal data abroad occur only under a valid mechanism of Article 33 of the LGPD.
6.2 Where the mechanism is standard contractual clauses, we use the clauses approved by ANPD Resolution CD/ANPD no 19/2024 — clauses from other jurisdictions (such as EU SCCs) are not used as a substitute. Where a transfer relies on another Article 33 mechanism (for example, an ANPD adequacy decision), that mechanism is recorded in our transfer records, available upon request.
6.3 As of the effective date of this Policy, international transfer recipients are: Google LLC (YouTube API Services), Netlify, Inc., OpenAI, LLC, Turso / ChiselStrike, Inc., and Stripe, Inc. (all United States); and Proton AG (Switzerland). Database edge replicas, if enabled, operate only in regions recorded in Annex III of the DPA.
7. Retention and Deletion
7.1 We keep personal data only for the periods stated in Section 2, after which it is deleted or irreversibly anonymized. When you delete your account, your account data, moderation configuration, and moderation outcome records are erased immediately, and we request revocation of your YouTube authorization with Google (you can also revoke it yourself at any time via Google's security settings — Section 4.3). An account that has purchased credits or a plan and whose organizations then all remain out of credits for 30 days is deleted the same way, after e-mail warnings sent every 7 days (Terms §17.3); funding any organization ends the countdown. The one exception is the consent-acceptance record (your e-mail, the document versions you accepted, timestamps, IP, and user agent), retained under Article 16, III of the LGPD for the regular exercise of rights in judicial, administrative, or arbitral proceedings: it is blocked from any other use, access-restricted, and kept for up to 10 years, after which the e-mail is erased and the record remains only in anonymized form. Commenter handles are the narrow exception to author-identifier non-retention: the commenter's plain public handle appears in the activity log for up to 30 days, is then erased automatically, and can be erased on demand at any time (Section 3.2). Pseudonymized author identifiers (such as hashed usernames) remain personal data and are not retained; we keep no pseudonymous profiles, no author channel IDs, and we do not track commenters across services. Comment text is retained only as part of moderation outcome records, for the periods stated in Section 2.
7.2 We may retain data beyond the stated periods only where required by law, court order, or for the regular exercise of rights in judicial, administrative, or arbitral proceedings (Art. 16 of the LGPD), restricted to that purpose.
8. Security
8.1 We apply technical and organizational measures proportionate to the risk, including TLS encryption in transit, least-privilege access, multi-factor authentication for administrative access, managed secrets storage, environment isolation, and an incident response plan aligned with the 3-business-day ANPD notification deadline of Resolution CD/ANPD no 15/2024. Details are in Annex II of the DPA, available upon request.
8.2 No method of transmission or storage is completely secure. If an incident occurs that may entail relevant risk or harm to you, we will notify you and the ANPD within the legal deadline, with the information required by law and the measures taken.
9. Legitimate Interest Notice
Where we rely on legitimate interest (security, abuse prevention, support records), we process only non-sensitive data strictly necessary for the specific purpose, we have documented a balancing test (LIA) in writing per the ANPD's 2024 Legitimate Interest Guidance, and we offer easy objection mechanisms. We never rely on legitimate interest for sensitive data, and we never use personal data to train AI models. You may request a summary of any balancing test from our DPO.
The separate assessment for optional public audience measurement is awaiting completion; the existing assessments above do not establish its lawful basis. Before activation, we will document its defined purpose, necessity, visitor expectations, potential impacts and safeguards. If legitimate interest is not suitable, collection will remain disabled while visitor-consent gating is designed. The deployment operator's opt-in is not visitor consent. You can object using the Audience measurement control below or contact our DPO to exercise your rights and request the completed assessment summary once available.
10. Your Rights
10.1 Under Article 18 of the LGPD, you have the right to: (I) confirmation that we process your data; (II) access; (III) correction of incomplete, inaccurate, or outdated data; (IV) anonymization, blocking, or deletion of unnecessary, excessive, or unlawfully processed data; (V) portability, as regulated by the ANPD; (VI) deletion of data processed with consent; (VII) information about the entities with which we share data; (VIII) information about the option not to consent and its consequences; (IX) revocation of consent; and (X) opposition to processing based on legitimate interest, where the legal requirements are met.
10.2 To exercise any right, contact our DPO at contact@Moderaty.com. We respond within 15 days. We may need to verify your identity before acting — a proportionate security measure. Requests are free of charge. If we cannot fulfill a request (for example, because the data was already deleted or must be retained by law), we will explain why within the same period.
10.3 You may also lodge a complaint with the ANPD (Autoridade Nacional de Proteção de Dados) at https://www.gov.br/anpd/pt-br.
11. Children and Adolescents
11.1 The Service is a professional tool directed exclusively at persons aged 18 or older and is not likely or foreseeably accessed by minors. We do not knowingly collect personal data directly from children or adolescents. If we learn that an account belongs to a minor, we will suspend and delete it.
11.2 For comment data that may relate to minors, see Section 3.3: we process all comment data to the highest standard because author age cannot be identified.
12. Cookies and Similar Technologies
12.1 The Service uses only strictly necessary cookies (session authentication, security, preference storage). We do not use advertising or third-party tracking cookies. You can block cookies in your browser, but essential cookies are required for login and security features to work.
12.2 If activated after the assessment, hosting/transfer records, retention verification and applicable notice period are complete, optional audience measurement covers only the five public pages (home, pricing, privacy, terms and DPA) and approved marketing-link clicks. Page addresses are rebuilt with only approved campaign values; duplicate campaign keys, fragments, advertising click IDs and arbitrary query values are discarded. URLs with embedded usernames or passwords, or recognized sensitive query keys, are excluded, as are account, login, consent, invitation and contact flows. A document that starts on or visits an excluded route cannot restart measurement within that document. External referrers are reduced to HTTP(S) origins; a private same-origin referrer suppresses collection.
12.3 This integration loads no tracking script and sends no explicit visitor identifier, account e-mail, channel or comment content, identify request, replay, heatmap or advertising conversion. It does not set analytics cookies or persist analytics identifiers in browser storage. The collector still receives the network IP address and browser user agent, processes them to derive pseudonymous session and visit information, and may derive approximate geography. A transient collector cache exists only in browser memory and is discarded on stop, opt-out or measurement-configuration changes. Limited payloads and no cookies do not guarantee anonymity or automatic LGPD compliance.
12.4 Use the Audience measurement control in the public footer to disable future collection in this browser. It stores only your opt-out preference. Do Not Track and Global Privacy Control are respected even if you allow measurement locally. A preference-storage failure disables measurement and shows a generic error. Changes in another tab stop future requests; choosing to allow measurement again may reload an eligible public page, and never enables a private document. Clearing browser storage removes the saved preference; browser privacy signals still apply. Already-started requests contain only the frozen safe public payload and may finish. Opt-out does not erase earlier records; contact our DPO under Section 10 for access, objection or deletion requests. Detailed data and backups are subject to the separate limits in Section 2.
13. Changes to This Policy
13.1 We may update this Policy with at least 30 days' prior notice, displayed prominently in the Service and sent by e-mail, with specific prominence given to any change in purpose, form, duration, controller identification, or sharing practices, as required by Article 8, §6, of the LGPD. Where processing is based on your consent and the change is incompatible with the original consent, you may revoke your consent before the change takes effect.
13.2 The current version is always available at /privacy, with its effective date and a change history.
14. Language and Governing Law
14.1 This Policy is published in English. A Portuguese version will be made available and, once published, will prevail for data subjects located in Brazil. This Policy is governed by Brazilian law, in particular the LGPD, the Marco Civil da Internet (Law no 12.965/2014), and the ECA Digital (Law no 15.211/2025).