Privacy Policy

How account and channel data is handled.

Build 2026.10.07.10

Last Updated: September 17, 2026

RODbot, available at rb.vox.io, is a live chat assistant for YouTube channel operators. This policy describes the information RODbot accesses through Google authorization, information you enter, and how those records support the features you choose.

Information Accessed and How It Is Used

RODbot processes information about the signed-in operator, the connected YouTube channel, people participating in its live chat, and subscribers whose information YouTube makes available. The categories below describe data accessed through the Google and YouTube APIs as well as data stored by RODbot. Available fields depend on the resource, event and permissions returned by Google or YouTube.

  • Google account identity and access requests: your Google account identifier and email address are stored to associate sign-in sessions with channel ownership, beta access and operator permissions. Google may provide a Brand Account or proxy identity. Beta-access requests and review records can also contain contact details you supply, request/review timestamps, approval status, IP address and browser user-agent information for access administration and abuse prevention. RODbot does not receive your Google password.
  • Authorization credentials: access and refresh tokens allow RODbot to access the YouTube features you authorize, including while your browser is closed. Tokens are encrypted before persistent storage.
  • YouTube channel details and statistics: API channel records can include the channel identifier, name, handle/custom URL, description, thumbnails, creation date, country, subscriber count and whether that count is hidden, video count and view count. RODbot caches channel information and keeps channel statistics in runtime state to identify channels and supply dashboard information and configured bot responses. Admin may also retrieve public channel names and handles to identify detached channels. Those public lookup results are cached for up to 24 hours and do not restore Google authorization.
  • YouTube broadcasts: broadcast identifiers, titles, descriptions, thumbnails, scheduled/actual start and end times, broadcast/privacy status, content details and live chat identifiers identify the selected stream and support stream discovery, status displays and live chat connection. RODbot caches API responses and stores selected broadcast/chat identifiers and connection state. A selected broadcast is deleted from YouTube only after a separate operator confirmation.
  • Live chat participants and messages: RODbot receives message identifiers, text, publication timestamps, message/event types, and author channel identifiers, display names, channel URLs, profile images and owner/moderator/member/verified indicators. It uses these fields to read commands, check command permissions, prevent duplicate processing and produce replies. Message and author details may be stored in command queues, runtime state and short-lived channel logs, according to the logging settings. Configured replies and acknowledgements are posted publicly to the connected YouTube live chat.
  • Membership, paid-support and other chat events: when included in a YouTube event, RODbot processes membership level, membership duration, upgrade status, gifted-membership counts and gifting channel/message identifiers; Super Chat and Super Sticker amounts, currency, display amount, tier, comments, sticker identifiers/descriptions and language; and moderation/deletion identifiers, affected channel names/identifiers, ban type/duration and poll question/status. Relevant fields are used for supported acknowledgements, event handling and diagnostics, and may appear in queued acknowledgements, duplicate-prevention state and short-lived channel logs. Public acknowledgement text depends on the operator's configuration.
  • Recent subscriber information: where YouTube makes it available, subscriber/subscription identifiers, channel names, descriptions, thumbnails and subscription timestamps support subscriber acknowledgements and duplicate prevention. API responses are cached; recent subscriber identifiers and acknowledgement state are retained in runtime state. Configured acknowledgements may identify the subscriber publicly in chat. YouTube controls which subscriber information is available.
  • Information you enter: channel profile details, links, command settings, fishing targets, catches and overlay settings configure bot behavior. Content included in bot replies or an enabled stream overlay is visible to its audience.
  • Session and diagnostic information: signed cookies maintain browser sign-in. Request, error, quota and resource-usage records help operators diagnose service failures and apply usage limits.

Storage, Access and Sharing

RODbot runs on Cloudflare, which processes and stores application data as our hosting provider. Google and YouTube receive the authenticated requests needed to perform the features you authorize. Channel operators and authorized RODbot administrators can view relevant settings, status and diagnostic records for operation and support. Browser overlay links should be shared only with the people or streaming software you intend to use them.

RODbot does not sell Google user data, use it for targeted advertising, or use it to train general-purpose AI models. OAuth tokens are not returned by public or browser-facing API responses. RODbot uses HTTPS, encrypted token storage, signed sessions and access controls to protect account data.

RODbot's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Retention and deletion: sessions expire automatically. Channel settings and runtime data remain associated with the connected channel until reset or offboarding. Disconnect Channel starts a persistent cleanup request that stops the bot, requests Google revocation, and deletes the selected channel's stored tokens, cached channel details, settings, catches, runtime state and channel logs. This action cannot be undone; reconnecting creates a new authorization.

If cleanup encounters a temporary failure, RODbot reports that it is incomplete, keeps the channel blocked, and retries about once a minute. Administrators can see pending requests and an attention flag after one hour. An encrypted revocation credential may remain while Google revocation is pending. Completed receipts are kept for 30 days; a minimal record containing the channel identifier, authorization version and deletion timestamps remains to prevent old requests from restoring deleted records.

RODbot checks Google authorization and refreshes channel details daily, including when the bot is removed from chat. Temporary provider failures retry hourly. API-derived channel details, broadcast identifiers and chat/subscriber runtime state are refreshed or cleared on a 28-day schedule, with short-lived response caches expiring within 30 minutes. If refresh fails at that deadline, the bot stays paused until authorization can be checked again. Independent settings, commands, fishing targets and catches are preserved during this expiry process. Confirmed credential revocation starts full channel cleanup. Storage or provider failures can delay physical deletion; administrators must resolve requests that remain pending.

Google sign-in identity-to-email mappings and tester approval/request records are account-level records shared across channels. Channel disconnect does not automatically remove these records. Contact us to request complete account/access removal. Administrators first check remaining linked channels and configured access, then use a persistent removal request to delete shared records and end access. Failed requests remain blocked and retry on scheduled maintenance. Completed account receipts contain counts for 30 days; minimal hashed security records prevent old sessions or cached approvals from restoring access. Pending/rejected tester requests expire after 90 days; approved records and identity mappings remain until account removal.

Retention Summary

During runtime operation, channel details/statistics may be refreshed from YouTube with a minimum ten-minute interval between refresh attempts. Broadcast, chat and subscriber requests follow the current runtime cadence and quota limits. These activity-driven requests are separate from the daily authorization/channel-details check and the 28-day refresh-or-clear maintenance described above; not every data category is refreshed daily.

Data Class Purpose Retention Deletion Trigger
Session Cookie Keep authenticated dashboard session Up to 30 days Logout, expiry, session invalidation
OAuth Token Bundle YouTube API access for connected channel While channel is onboarded Disconnect or app-side deletion; encrypted revocation credentials remain only while the revocation request is pending
Cached YouTube Data Channel details, stream status and acknowledgement state Daily channel refresh; API-derived state cleared by the 28-day maintenance deadline Refresh, automatic expiry, verified revocation or channel deletion
Channel Config Command/chat/profile behavior While channel is onboarded Disconnect Channel, channel reset or offboarding request
Operational Logs/Telemetry Reliability, quota, and diagnostics Channel logs are available through a 2-day query window. Scheduled pruning removes rows older than 2 days; additional write-time pruning uses a 3-day cutoff. Billing trends use a 72-hour window; channel-attributed quota counters are kept for up to three quota days Automatic retention pruning; selected-channel logs and quota attribution are also removed during offboarding

User Controls and Deletion

You can disconnect and revoke access at any time using the in-app Disconnect Channel action or from your Google account permissions page.

Remove Bot pauses automation and keeps authorization and settings. Sign Out ends the browser session. Disconnect Channel deletes that channel's RODbot data and requests Google revocation. Google revocation may affect other channels or clients using the same Google authorization, which may then need to reconnect. These actions do not delete your YouTube channel or its videos.

Project-level provider usage totals and hosting/security records are separate from channel chat logs. Email-level beta approvals and support correspondence also have a separate purpose; contact support if you want these reviewed as part of an account-wide deletion request. Revoking access directly at Google and requesting deletion of all RODbot records are separate controls; contact support for assistance with a complete deletion request.

If you need channel offboarding or data deletion assistance, contact support at wannaseemyrod@gmail.com. We process requests to delete stored YouTube API data as soon as possible and within 7 calendar days of the request. This is a deletion deadline, not just a target for acknowledging your message. Contact support if an in-app cleanup request remains pending.

Third-Party Policies

OAuth Scope to Feature Mapping (Least Privilege)

Scope Feature Use Why Required
https://www.googleapis.com/auth/youtube.force-ssl Read channel, subscriber, live broadcast and chat resources; post authorized bot replies; delete a selected broadcast only after operator confirmation. Required for authenticated live chat read + insert operations from channel owner identity.
https://www.googleapis.com/auth/userinfo.email Bind Google identity email for beta-access approvals, admin controls, and session ownership. Required for operator identity association and access governance.
openid Bind stable Google subject (`sub`) for session and channel ownership linkage. Required for consistent identity mapping across reauth and session refresh.

RODbot uses incremental authorization: initial account sign-in requests identity scopes first, then requests YouTube runtime scope in a second OAuth step.

Material changes to how RODbot uses Google user data will be reflected in this policy and communicated through the application. For privacy or deletion questions, contact wannaseemyrod@gmail.com.