Privacy Policy
Warden · Shpaga Chat Moderator (https://yt.shpaga.party) · Last updated: October 7, 2026
Warden ("the Service", "we") is a private live chat moderation tool operated by Yaroslav Zakabluk, an independent developer based in Kyiv, Ukraine. The Service helps a single YouTube channel and the moderators appointed by that channel keep the live chat of the channel's own broadcasts free of spam and abuse.
1. Use of YouTube API Services
The Service uses YouTube API Services. By using the Service you agree to be bound by the YouTube Terms of Service. Information obtained through YouTube API Services is also governed by the Google Privacy Policy. Our use of information received from YouTube API Services adheres to the YouTube API Services Developer Policies, and Warden's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
2. Who can use the Service
Access is limited to the channel owner and moderators appointed by the channel. Accounts are created by the channel's administrator; there is no public sign-up. The Service is not open to the general public.
3. Information we access and collect
- Bot account authorization (Google OAuth): the channel's dedicated bot Google account, which the channel has made a moderator of its live chat, authorizes the Service with the
youtube.force-ssl scope and the openid email scopes. We store the bot account's email address, YouTube channel ID, channel title and profile image to show which account is connected.
- Moderator YouTube accounts (optional): a moderator may connect their own Google account with the same scopes so that chat messages they write in the dashboard are posted under their own YouTube name. For such an account we store its email address, YouTube channel ID, channel title and profile image and its OAuth tokens, and use them only to post the messages that moderator writes. Deleting messages, timeouts and bans are always performed by the bot account.
- OAuth tokens: access and refresh tokens of the bot account and of connected moderator accounts, stored encrypted on our server. The bot's tokens are used only to read the live chat of the channel's broadcasts and to perform moderation actions in it (deleting messages, timeouts, bans, posting messages) requested by authorized moderators or by the channel's configured automatic rules; a moderator's tokens are used only to post the chat messages that moderator writes.
- Public data of the channel's broadcasts: broadcast ID, title, live chat ID, start/end time and concurrent viewer count, as returned by the YouTube Data API.
- Live chat data of the channel's broadcasts: message ID, message text, timestamp, and the author's YouTube channel ID, display name, profile image URL and chat role (owner, moderator, member), as returned by the YouTube Data API.
- Moderator accounts: name, email address and a hashed password of each moderator, their role, and the time they were last active.
- Moderation logs: which messages were flagged or deleted, which users were timed out, banned or unbanned, by whom (the bot or a named moderator), when, the reason, and notes moderators write for each other.
4. How we use information
- Showing the live chat of the channel's broadcasts to its moderators in the moderation dashboard.
- Automatically detecting spam, scam links, flooding and other messages that violate YouTube Community Guidelines or the channel's chat rules, and performing the moderation actions the channel has configured.
- Performing moderation actions requested by moderators and posting the channel's informational announcements through the bot account.
- Posting the chat messages a moderator writes under that moderator's own YouTube name, if they have connected their account.
- Keeping an audit log of moderation actions for the channel team.
We do not sell, rent or share user data with third parties, and we do not use it for advertising, profiling, or any purpose other than moderating the channel's live chat.
5. Sharing
Data is visible only to the channel owner and its authorized moderators. Moderation actions are sent to YouTube through the YouTube Data API. We may disclose information only if required by law.
6. Cookies and device storage
The dashboard uses only strictly necessary cookies for signed-in moderators: a session cookie and a CSRF protection cookie. It also stores the moderator's interface preferences (for example the colour theme) in the browser's local storage. We do not use analytics or advertising cookies, and we do not place any cookies or other data on the devices of the channel's viewers.
7. Storage and retention
- Live chat messages and the violations detected in them are kept for no longer than 30 days.
- Moderation and audit logs are kept for no longer than 30 days.
- Profile data of chat participants (display name, profile image) is refreshed whenever they write in the chat and is deleted when they have not been seen for 30 days, unless a moderator keeps them on the channel's whitelist or a moderation restriction is still active.
- Data obtained from YouTube API Services is refreshed or deleted at least every 30 days, as required by the YouTube API Services Developer Policies.
- OAuth tokens are deleted immediately when access is revoked or the account (bot or moderator) is disconnected.
8. Revoking access
The owner of the bot account and any moderator who connected their own account can revoke the Service's access at any time via the Google security settings page. The channel administrator can disconnect the bot account, and moderators can disconnect their own account, in the dashboard. After revocation we delete the stored tokens and stop using that account.
9. Deleting your data
You can request deletion of any data related to you, including data about your participation in the channel's live chat, by emailing slavious@gmail.com. We will delete it within 7 days.
10. Security
All traffic uses HTTPS. OAuth tokens are encrypted at rest and are never shown in the dashboard. Access to the dashboard requires signing in with a moderator account created by the channel administrator; passwords are stored hashed, and every action is checked against the moderator's permissions and recorded in the audit log.
11. Changes
We may update this policy. The date at the top shows the latest revision.
12. Contact
Yaroslav Zakabluk · Kyiv, Ukraine · slavious@gmail.com