Bonsai Global
Privacy Policy
This policy explains how Comment Guardian handles information when authorized YouTube channel owners use the service.
Effective September 2, 2026
1. Who operates this service
Comment Guardian is operated by Bonsai Global. Questions or privacy requests can be sent to niko@bonsaiglobal.io.
2. Information we collect
When an administrator signs in or connects a channel, we receive the Google account identity needed to authenticate the administrator, including email address and basic profile information. Through the YouTube Data API, we process channel and video identifiers, titles, comment and comment-thread identifiers, comment text, publication times, moderation status, and available commenter channel identifiers and display names.
We also create moderation records such as classifications and explanations, confidence estimates, commenter history, human decisions, action results, audit events, and limited service-usage and error information. OAuth refresh tokens are encrypted and stored only on the server.
3. How we use information
We use this information only to authenticate authorized administrators; retrieve and organize comments from their connected channels; identify possible spam, abuse, threats, scams, hate, or other policy concerns; display a human-review queue; carry out actions selected by an authorized moderator; prevent duplicate processing; and maintain security, reliability, and an audit trail.
Comment Guardian is not an advertising service. We do not sell personal information or use Google user data for advertising.
4. Google API Services
Comment Guardian’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. The YouTube permission requested by the moderation connection is used to read comments and moderation states and to perform only the moderation actions authorized through Comment Guardian.
5. AI processing
Comment text and relevant moderation context may be sent to Google’s Gemini service to produce structured moderation recommendations. In recommendations-only mode, Comment Guardian does not automatically reject comments or block authors. An authorized moderator decides what happens. Automatic removals and blocks are not enabled by default.
6. Storage and sharing
Application data is stored in Google Cloud services used by Comment Guardian, including Firestore, Secret Manager, and Cloud Run. Information is shared with Google service providers only as needed to operate authentication, YouTube access, hosting, storage, security, and comment classification. We may also disclose information if required by law or necessary to protect the service, its users, or others. We do not sell or rent this information.
6A. Customer workspaces and access
Each licensed customer’s channels, comments, policies, commenter history, scans, activity, analytics, and usable YouTube credentials are isolated within that customer’s workspace. Access requires Google identity authentication and an active workspace membership approved for that customer.
Bonsai Global’s licensing administration is separate from access to moderation data. Managing a customer’s license does not itself grant routine access to that customer’s comments or YouTube moderation data. The product does not provide a feature for browsing a customer’s workspace as that customer.
7. Retention and deletion
Comment and audit records are retained while needed to operate the moderation service and preserve accountability, including records of comments that may no longer be available through YouTube after rejection. OAuth tokens are retained until the channel is disconnected, access is revoked, or the service is discontinued. An authorized administrator may request deletion of stored account and channel data by contacting us. We may retain limited records where required for security, legal compliance, or a documented audit obligation.
8. Your choices
Administrators can stop future Google API access by disconnecting a channel in Comment Guardian or revoking access from their Google Account connections. Disconnecting removes Comment Guardian’s usable authorization without changing the underlying YouTube account. License suspension or revocation stops workspace and background access but does not delete customer data. Data export and deletion are separate requests; contact us to request either.
9. Security
We use server-side OAuth handling, encrypted credential storage, access controls, protected administration routes, request validation, and audit logging. No system can guarantee absolute security, but we limit access and avoid exposing refresh tokens to the browser or application logs.
10. Changes to this policy
We may update this policy as the service changes. The effective date above will be revised when material changes are published.