Privacy Policy for Moddy AI
Last updated: 05.01.2025
1. Introduction
Welcome to Moddy AI ("we", "our", "us"). We are committed to protecting and respecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your personal data when you use our AI moderation service for user communities. This policy applies to users in the European Union (EU) and the United States of America (USA).
By using our services, you agree to the collection and use of information in accordance with this Privacy Policy.
2. Information We Collect
To provide and improve our services, we collect the following types of information:
- Personal Data: This includes information such as your name, email address, and any other details you provide when registering or using our service.
- Message Data: For messages flagged as violations, we collect:
- The content of the message.
- Metadata such as the sender, date, and the response from our moderation function.
- Media Data: Images and voice messages associated with violations are collected and stored separately in encrypted form.
- Usage Data: We collect statistics on how much your community uses different resources (e.g., the number of messages processed).
- Device and Log Information: We may collect information about the device you use to access our service, such as your IP address, browser type, and operating system, for security and analytics purposes.
Categories of Personal Information Collected (For USA Users)
In the past 12 months, we have collected the following categories of personal information:
- Identifiers (e.g., name, email address)
- Internet or other electronic network activity information (e.g., IP address, browser type)
- Audio, electronic, visual, or similar information (e.g., voice messages, images)
- Inferences drawn from the above information
3. How We Use Your Data
We use the data we collect to:
- Provide the moderation service, including processing messages in real-time to detect violations based on the rules you configure.
- Display the history of violations, including messages and media, to community owners and admins in the dashboard, enabling them to review what our moderator considered a violation and the punishments executed.
- Analyze usage statistics for our internal purposes, such as optimizing pricing in our application.
- Respond to user queries and support requests.
- Comply with legal obligations.
Lawful Basis for Processing (For EU Users)
We process your personal data based on the following lawful bases:
- Contract: To fulfill our contract with you by providing AI moderation services.
- Legitimate Interests: To analyze usage statistics and improve our service.
- Legal Obligation: To comply with applicable laws and regulations.
Purposes for Collection (For USA Users)
We collect personal information for the following purposes:
- To provide and maintain our service
- To improve our service
- To communicate with you
- To comply with legal obligations
4. Data Retention
We retain data as follows:
- Violation Data: Messages and media flagged as violations are retained for one week after the violation occurs, after which they are permanently deleted from our systems.
- Account Information: Personal data and other account-related information are retained until your account is deleted. Upon account deletion, requested via nillcon248@gmail.com, all account data is permanently removed within 30 days.
- Usage Statistics: Aggregated usage data may be retained indefinitely for internal analysis and service improvement, but it is anonymized and does not identify individual users.
Users may request deletion of their account-related information by contacting us at nillcon248@gmail.com. Deletion requests are processed within 30 days.
5. Data Sharing
We do not share your personal data with third parties, except:
- Service Providers: We use Google services (Firestore for database, Firebase Storage for media) to store and process data. These providers act as subprocessors and do not process user data beyond providing storage and infrastructure support.
- AI Moderation: We may use third-party AI services (e.g., OpenAI or Google Gemini) to analyze messages for moderation. Only flagged violation data is temporarily processed by these services and is not retained by them.
- Legal Requirements: When required by law or to protect our legal rights.
Sharing of Personal Information (For USA Users)
We do not sell your personal information. We share your personal information only with service providers (e.g., Google, OpenAI) as described above, under strict data processing agreements.
6. Data Security
We implement reasonable security measures to protect your data:
- Media Data: Images and voice messages associated with violations are encrypted using AES-256 with a single key stored securely in secrets, ensuring protection against unauthorized access.
- Message Data: Message text and metadata are stored in our Firestore database without encryption, but access is restricted to authorized personnel only via strict access controls.
- Storage: We use Firestore as our database and Firebase Storage for media, both of which include additional security features provided by Google.
7. AI Moderation and Custom Rules
Our service uses Large Language Models (LLMs) to moderate messages based on custom rules defined by users (e.g., restricting casino ads or dog-related messages). Messages are processed in real-time by AI systems:
- Only messages flagged as violations are stored temporarily (for one week) and displayed in the dashboard.
- Non-flagged messages are not retained or stored beyond the initial processing for moderation.
- Third-party AI providers (e.g., OpenAI, Google Gemini) may process flagged messages but do not retain them after analysis.
8. Your Rights
For EU Users
As a user in the EU, you have the following rights under GDPR:
- Access: You have the right to access the personal data we hold about you.
- Correction: You can request corrections to any inaccurate or incomplete data.
- Deletion: You can request the deletion of your personal data, with exceptions as required by law.
- Restriction: You can request the restriction of processing of your personal data.
- Portability: You can request a copy of your personal data in a structured, commonly used format.
- Objection: You can object to our processing of your personal data if it is based on legitimate interests, and we will stop processing unless we have compelling legal reasons.
To exercise these rights, email us at nillcon248@gmail.com. Requests are processed within 30 days.
For USA Users (CCPA Compliance)
As a user in the USA, you have the following rights under the California Consumer Privacy Act (CCPA):
- Right to Know: You have the right to know the categories of personal information we collect, the purposes for which we use it, and the categories of third parties with whom we share it.
- Right to Delete: You have the right to request the deletion of your personal information, with exceptions as required by law.
- Right to Opt-Out: We do not sell your personal information, so this right does not apply. If this changes, we will notify you and provide an opt-out mechanism.
To exercise your CCPA rights, submit a request via email to nillcon248@gmail.com or through our website at https://moddy-ai.com. We will verify your identity and respond within 45 days. There is no fee for processing requests unless they are excessive or unfounded.
9. International Data Transfers
Your data may be transferred and stored on servers outside your country of residence, including in the United States, due to our use of Google services (Firestore, Firebase Storage).
For EU Users
For EU users, we ensure that data transfers to the US are protected by Standard Contractual Clauses (SCCs) as provided by Google. No other international service providers are currently used beyond Google’s infrastructure.
10. Cookies and Tracking Technologies
Our website uses cookies and similar tracking technologies to improve functionality and monitor usage patterns. You can configure your browser to reject cookies, but this may limit the functionality of the service.
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. Any changes will be communicated to you via the platform or by email. Please review the policy regularly to stay informed about how we are protecting your information.
12. Contact Us
If you have any questions or concerns about this Privacy Policy or the way your personal data is handled, please contact us at:
- Email: nillcon248@gmail.com
- Address: <Will be added later>
For EU Users
For GDPR-related inquiries, contact our designated Data Protection Officer (DPO) at nillcon248@gmail.com. If no DPO is appointed, these responsibilities are handled by our privacy team at nillcon248@gmail.com.
For USA Users
To exercise your CCPA rights or for other privacy inquiries, contact us at nillcon248@gmail.com.