The Litter Tray

Privacy Policy

Who we are: The Litter Tray, based in the Isle of Man.

Postal address: Mike @ PO Box 5, Ramsey, Isle of Man, IM99 4RE.

Email: office@thelittertray.app

Last updated: 20 September 2026

The Litter Tray is a moderation tool for YouTube channel owners. You connect your own channel, we keep a private archive of its comments, and an AI classifier helps you spot bad-faith attacks so you can deal with them without living inside YouTube Studio.

This policy covers two groups of people, and we address each honestly:

  1. You, our customer: the channel owner with an account.
  2. Commenters on your channel: people whose public comments pass through the service. They never signed up for anything, so they get their own section below.

Our role in plain words: for your account data we are the controller: decisions about it are ours. For your channel's comment data we are your processor: we handle it on your instructions, and the moderation decisions are yours. For one limited slice (keeping the service itself safe and operating the safety-evidence record described in section 2) we act as an independent controller in our own right.

The short version

  • We collect what we need to run the service and nothing more.
  • We do not sell data. We do not run advertising. Analytics, if you accept them, are described in the Analytics section below.
  • Comment text is sent to OpenAI's API for classification. No AI model is trained on it.
  • Your channel's comments and moderation record are a private working copy of what the tray observed, not a complete or permanent YouTube history.
  • A comment not returned by a successful check is marked unavailable, without assuming who removed it. Some stored text can later be removed; the moderation record described below currently keeps its text.
  • The Free Plan is kept by being used: a free tray nobody signs into for 3 days is paused and its owner is emailed, and one nobody signs into by day 5 is closed and wiped. Signing in keeps it. Paid plans do not pause for inactivity.
  • We keep copies of the emails we send you, and the delivery reports that come back. Section 1.1 says what is in them.
  • The service is hosted in the United Kingdom (AWS London region). We are based in the Isle of Man, which has GDPR-equivalent data protection law.

Analytics

If you accept analytics on the banner, we load Google Analytics 4 so we can see which pages are used, both on the marketing site and in the app. It does not run until you accept. Declining is one click and is remembered for 12 months. You can change your mind from Analytics choices in the footer; a decline after an accept takes effect from the next page view.

We do not send Google your name, email address, tray id, comment text, viewer names, or query strings that might carry tokens. Google Signals is off. Ads personalisation is off. We ask Google to keep the data for the shortest retention they offer.

Google acts as a processor. Google may process the data outside the UK and EU, under their own terms. Their role is described in the Google Privacy Policy.


1. Information for customers (channel owners)

1.1 What we collect

Account data. Your email address, login credentials (stored as a salted hash; we cannot read your password), and security records such as login times, IP addresses, and browser type. We keep these to run your account and to spot break-in attempts.

YouTube connection data. When you connect your channel through Google sign-in, Google gives us OAuth tokens that let the service act with your channel's authority. We store those tokens encrypted on our servers. We never see your Google password.

Your channel's name, and your video titles. When you connect your channel we read its name, so the service can show you which channel is connected. As comments arrive we read the titles of your own videos, so that a comment can be shown beside the video it was posted on, and so the classifier can use the title as context if you switch that on. We store both. We read nothing about any other channel, and nothing about anyone's viewing or watch history.

Your channel's comment data. See section 3: this is the heart of the service and gets its own section.

How much AI reading your tray has used. A count per day of how many AI prompts your tray used and their estimated cost. It contains no comment text. We keep it for the life of your account, and it stays even if you disconnect your channel or wipe your tray's imported data, because it is how plan allowances are enforced.

The plan you chose before signing in. If you pick a paid plan on our website and then sign in, we keep that choice on our server for 24 hours so the billing page can offer it to you. It is removed once used, or after 24 hours.

Support and correspondence. If you email us, we keep the thread so we can reply and so there is a record of what was agreed.

Letters we send you. When the service emails you, for example a welcome, a plan change, or a notice about your tray, we keep a copy: the address it went to, the subject, the wording that was sent, and what happened to it. A letter waiting to go sits in a queue on our side until it is sent or given up on. We keep these so that we can tell you what we told you, and so that a question about an email has an answer. The queue and the copies live with your tray and are deleted when your account closes.

Delivery reports, and the do-not-write list. Our email provider reports back what happened to each letter: delivered, delayed, bounced, or reported as spam. We store those reports as they arrive, including the provider's own message about them. An address that hard-bounces, or that reports us as spam, goes on a suppression list and we do not write to it again. That list holds the address and the reason and nothing else, and it is the one email record that deliberately outlives an account: it is how we keep honouring "stop emailing me" once there is no account left to look it up against. We do not switch on open tracking or click tracking. If a provider ever sends us a report of that kind anyway, it is stored with the others and flagged for us to look at, and it is not used to build a picture of you.

Waiting-list addresses. There is no public waiting list. Sign in with Google to create an account. We do not collect an email address from a waiting-list box, because that box is gone.

Addresses collected while that box existed may still be held. For those historical records this is everything we hold about the person who typed them: the address, exactly as typed, and the time it was given. They created no account. They were stored for one purpose, to write when a tray was ready, and nothing was sent before then. The basis is the consent given at the time. We keep a remaining address until we have contacted the person about a place or until they ask to be taken off, whichever comes first; to be taken off, email office@thelittertray.app from that address and we will remove it.

24 August 2026. The two paragraphs above replace the tester-week wording, which read in the present tense: "If you have put your email address into the waiting-list box, you are not a customer yet and this paragraph is everything we hold about you: the address, exactly as you typed it, and the time you gave it. It creates no account. We store it for one purpose, to write to you when a tray is ready for you, and we send nothing before then. The basis is your consent: you gave us the address so we could contact you." That was true while the waiting-list box was open. The public form closed on 23 August 2026. Historical records, if any remain, are still described here so this policy does not pretend they were never collected.

What we do not collect: advertising identifiers, payment details, or any profile for advertising. If you accept analytics, Google Analytics sets its own cookies and records which pages you visit, with your IP address shortened; you can decline or change your mind at any time from Analytics choices in the footer. The Free Plan needs no payment method at all, and on a paid plan your card is handled by Paddle, our payment processor and merchant of record: those details go to them and never reach us (section 4).

1.2 How we use it

  • To provide the service: mirroring your channel's comments, classifying them, and carrying out the moderation actions you configure or approve.
  • To secure the service: authentication, rate limiting, and intrusion detection.
  • To communicate with you about your account and the service.
  • To meet legal obligations that apply to us.

We count which product features each tray uses, and when. No comment content or viewer identity is included.

Our legal bases under Isle of Man, UK, and EU data protection law: performance of our contract with you (running the service you asked for), legitimate interests (keeping the service secure), and legal obligation where the law requires something of us. For your channel's comment data we act as your processor; the lawful basis for that processing is yours as channel owner, described in section 2.

1.3 YouTube API Services: required disclosures

The Litter Tray uses YouTube API Services to read your channel's comments and to carry out moderation actions on your behalf.

  • By using The Litter Tray, you also agree to the YouTube Terms of Service.
  • Google's handling of your data is described in the Google Privacy Policy.
  • You can revoke The Litter Tray's access to your Google account at any time via Google's security settings. Revoking access stops the tray for that channel. Wiping the imported archive is a separate, deliberate Disconnect inside the app.

Limited Use. The Litter Tray's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. In plain words: data we obtain through YouTube API Services is used only to provide the moderation features you see in the app. We do not use it for advertising, we do not sell it, and no human at The Litter Tray reads it except to run the service, with your permission, for security reasons, or where the law requires.

Retention note. Stored words are what the tray last observed; they are not continuously re-fetched. Checking whether a comment is still available is not the same as refreshing its text. Section 3.3 describes current retention behavior.

1.4 AI classification

We send comment text and identifiers, display names, relevant channel and thread context, and your moderation policy to OpenAI to assess comments. The classifier's verdicts are stored in your archive alongside the comments they concern.

OpenAI's commercial API terms exclude training AI models on customer inputs by default, and we send the minimum fields necessary. We do not train, and do not allow anyone to train, any AI model on your data or your commenters' data.


2. Information for commenters

If you have commented on a YouTube channel that uses The Litter Tray, this section is for you. We will be straight with you about what happens.

2.1 What we hold and why

The service keeps a private, per-channel copy of the comments posted publicly to that channel: the comment text, your public display name and channel ID, and timestamps: the same information anyone could see on the video's public comment section, plus a record of any moderation decisions made about those comments.

The channel owner uses this archive as their moderation record: to review what the classifier flagged, to see a commenter's history on their own channel, and to keep evidence when they are targeted by harassment.

2.2 Legal basis, and who is responsible

For the archive, the channel owner is the controller and we act as their processor: we hold and process the archive on their instructions, and the moderation decisions are theirs. The basis relied on is legitimate interests: a channel owner's interest in moderating their own community and in keeping evidence of harassment directed at them. What we hold is what you chose to post publicly to their channel.

For one limited slice we act as an independent controller in our own right, also on the basis of legitimate interests: keeping the service itself safe: abuse prevention, security, and operating the safety-evidence rules described in 2.3 consistently across the service.

Either way, the archive is private to that channel: it is not published, shared between channels, sold, or used for advertising, and no AI model is trained on it.

Where a channel owner has invited team members to help moderate, those members act under the owner's authority and not on their own account: the owner decides who is invited, in which role, and when that access ends, and the responsibility for what is done with the archive stays the owner's throughout. It does not make each member a separate controller, and it does not widen who the archive is for. Section 3.1 says who can see it.

2.3 Comments that become unavailable

What happens depends on what the tray currently keeps:

  • Unavailable comments. If a successful check no longer returns a comment, we mark it no longer available on YouTube. That does not prove who removed it, or why. Failed or incomplete checks do not count as absence.
  • Ordinary stored text. Outside the kept moderation record, stored text can later be removed after a delay measured from the last time we still saw the comment. Checks are bounded, so an unavailable comment may be noticed later in a large archive. Comments YouTube still returns can keep the words we last stored.
  • Kept moderation record. Comments the owner has acted on, comments waiting on a decision, comments by banned or probated authors, and name-pattern matches currently keep their stored text even if they become unavailable on YouTube. This describes the product's present retention rules; it does not establish a YouTube policy exemption or promise permanent storage.

Account closure and Disconnect wipe imported comment data from the live tray. Backups are separate; see section 5.

2.4 Your rights

You have rights over personal data we hold about you, including the rights to access it, to correct it, to object to the processing, and to ask for erasure. Email office@thelittertray.app and tell us the channel and comment(s) concerned; we will respond within one month.

For comments outside the kept moderation record, you can delete the comment on YouTube and also ask us directly. We will tell you what this tray still holds.

If you ask us to erase comments in the private moderation record, we will respond within one month and explain what we can do with those records. This policy does not decide the outcome of that request in advance. You can complain to a supervisory authority (section 7) if you are unhappy with the answer.


3. The comment archive (both audiences)

3.1 What it is

A private mirror, per channel, of that channel's comments and moderation history. Three sets of eyes can reach it and no others: the channel's owner; any team members the owner has invited into that channel, who see it because the owner decided they should and who act under the owner's authority (2.2); and our systems operating the service. The owner chooses each member's role when they invite them and can withdraw the access at any time. Channels cannot see each other's archives.

3.2 Where moderation actions come from

Moderation actions (holding, removing, or restoring comments) are carried out on YouTube using the channel owner's own authority via the YouTube API: the same actions they could take themselves in YouTube Studio. The Litter Tray does not have or use any authority over YouTube content beyond what each channel owner grants for their own channel.

3.3 How long it is kept

The categories in section 2.3 describe which comments currently keep their text. Other stored text can be removed after a delay from the last successful sighting when a later successful check shows it is unavailable. This is not a guaranteed deletion date measured from removal on YouTube, or a refresh of every stored field.

Disconnect and account closure wipe imported comment data from the live tray. You can also request deletion from us; see section 5.


4. Who we share data with

We share data with the small set of service providers needed to run The Litter Tray, and no one else. We do not sell personal data. We have no advertising partners.

Provider What they do What they handle
Amazon Web Services Cloud infrastructure: the service is hosted in the United Kingdom (AWS London region) All service data, encrypted in transit; credentials and OAuth tokens additionally encrypted at rest
OpenAI AI classification (commercial API) We send comment text and identifiers, display names, relevant channel and thread context, and your moderation policy to OpenAI to assess comments. No training on this data.
Google / YouTube The YouTube API itself The comment and moderation data originates from and returns to YouTube under the channel owner's authority
Cloudflare DNS, and the proxy and security layer sitting in front of the website: every request for a page reaches Cloudflare before it reaches our server Visitor IP addresses and request metadata (which page was asked for, when, and from what kind of browser), used to route and cache traffic and to turn away attacks
Paddle Payments: the merchant of record for paid plans. Paddle runs the checkout, takes the payment, and issues your receipt. The Free Plan never touches them Billing data: your name, email address, payment details and transaction history, which Paddle holds as an independent controller under its own privacy policy. Card details go to Paddle directly and never reach us. We keep our own record of your Paddle customer and subscription identifiers, and the signed notices Paddle sends us about your subscription (which carry your name, email address, plan and amount, never card numbers), for as long as you have an account and afterwards for as long as accounting law requires.
SMTP2GO and Amazon SES Sending email: every letter the service sends you, such as sign-in notices, receipts, alerts and digests, is delivered by one of these two Your email address and the full content of those letters, which can quote a fragment of a comment
Telegram (optional) Optional notifications, and only where you have connected a Telegram chat to receive them. Disconnecting it changes nothing you see in the app Your Telegram chat identifier and the text of those notifications. They are account notices and never quote a comment.
Notion (optional) Carries our own operational notifications, and only where the person running the service has connected a Notion account to receive them. Disconnecting it changes nothing you see in the app Notification titles and text, which can quote a fragment of a comment

We may also disclose data if the law genuinely requires it (a valid legal demand), or to protect someone from serious harm. If that ever happens we will tell the affected customer unless we are legally barred from doing so.

5. Retention and deletion

  • Waiting-list addresses: no new addresses are collected. Any address still held from the retired waiting-list box is kept until we have contacted you about a place or you ask to be removed, whichever comes first. Email office@thelittertray.app and we take you off the list. 24 August 2026: this bullet used to describe a live waiting-list box in the present tense; that box closed on 23 August 2026.
  • Account data: kept while your account exists, then deleted.
  • Moderation record: the current keep-text categories are described in section 2.3; imported records are removed from the live tray by its wipe paths.
  • Ordinary archived comments: stored text may later be removed as section 3.3 describes. Identifying rows and other metadata can remain until a live-tray wipe.
  • Live-tray wipe: closing your account, Disconnect in the app, and the Free Plan attendance rule wipe imported YouTube data from the live tray when those paths run. You can also ask us to delete it. Revoking access in Google's security settings stops the tray; it does not itself wipe the archive.
  • Free Plan attendance. The Free Plan is kept by being used, and that is a term of the plan rather than a technical limit. The rule is this: a free tray that nobody who administers it has signed into for 3 days is paused, and we email its owner to say so; if nobody has signed in by day 5, the tray is closed and its imported YouTube data is wiped, exactly as if the owner had closed it themselves. Signing in before closure stops the clock and puts the tray back as it was. We never close a tray this way without having written to its owner first, and a tray we cannot reach is not closed at all. Paid plans are not subject to any of this: they do not pause for inactivity and are never closed for going unused.
  • Letters we sent you, and the queue: kept with your tray while your account exists, and deleted when it closes.
  • Delivery reports: kept while they are useful for keeping our sending healthy. We do not delete these on a timer today, and we will say so here if that changes.
  • Suppression list: kept until you ask us to take the address off it. It survives the closing of an account on purpose, so that a closed account cannot be the reason we start writing to somebody again.
  • Backups: Backups made before a disconnect or switch are retained separately. Backup rotation does not guarantee a fixed deletion date.
  • Correspondence: kept as long as needed to handle the matter and keep a record of what was agreed.

6. International transfers

The service is hosted in the United Kingdom (AWS London region). We are based in the Isle of Man, whose data protection law is GDPR-equivalent (Data Protection Act 2018 and the GDPR (Isle of Man) Order) and which holds an adequacy decision from both the EU and the UK. Some of our service providers (section 4) may process data in other countries, including the United States, OpenAI's API classification in particular; where they do, transfers rest on recognised safeguards such as adequacy decisions and standard contractual clauses. If you are in the US: this policy applies to you too; we simply hold everyone to the same standard rather than running separate regimes.

7. Your rights and how to complain

Wherever you are, you can ask us: what we hold about you, for a copy of it, to correct it, to delete it (subject to section 2.4's honest caveat), to restrict or object to processing, and to receive your data in a portable format. Email office@thelittertray.app. We answer within one month and we do not charge.

If you are unhappy with our answer you can complain to a supervisory authority: the Isle of Man Information Commissioner (our regulator), the UK ICO if you are in the UK, or your national data protection authority if you are in the EU/EEA.

8. Security

The service sits behind authenticated logins with two-factor authentication for operators, encrypted connections everywhere, encrypted storage for credentials and OAuth tokens, and infrastructure hardening that we keep current. No one can honestly promise perfect security; we promise careful engineering and prompt honesty if anything ever goes wrong. If a breach affects you, we will notify you and the regulator as the law requires.

9. Children

The Litter Tray is for YouTube channel owners aged 18 or over. We do not knowingly provide accounts to anyone younger, and we do not knowingly collect data about children. Comments on customers' channels are governed by YouTube's own age rules; where YouTube marks content as made for kids, comments are disabled by YouTube and there is nothing for us to process.

10. Changes to this policy

If we change this policy we will update the date at the top and, for anything that matters, tell customers directly before the change takes effect. We will not quietly weaken it.

11. Contact

The Litter Tray
Mike @ PO Box 5, Ramsey, Isle of Man, IM99 4RE
office@thelittertray.app