Last updated · September 8, 2026
MeowlyVA ("we", "our", "us") operates the MeowlyVA website and community platform. This Privacy Policy explains what information we collect, how we use it, and your rights regarding that information.
When you create a MeowlyVA account, we collect your email address, username, and optionally your Discord identity if you authenticate via Discord OAuth.
We may collect anonymous usage analytics (e.g., feature usage frequency, crash reports) to improve the application. This data does not include personal information or video content.
To protect the community, we may process account, device, network, and activity signals for abuse and ban-evasion detection. This includes canonical email hash, email domain, and disposable-email status; edge TLS and HTTP/2 fingerprints when our edge provider supplies them; message and reply behavior summaries; observed Discord aliases; Minecraft names and non-reversible skin hashes; and Twitch follow timing already collected by MeowlyVA.
When an authorized member of the MeowlyVA business operations team connects a YouTube channel owned by MeowlyVA (currently the "Meowlyva" main channel and "Meowlyva VODs" VOD channel) through our internal Business Operations Viewer, we collect and store the following data server-side on our infrastructure:
This data is collected by authenticated calls to the YouTube Data API v3 and the YouTube Analytics API using the credentials granted at OAuth time, and is refreshed by a daily scheduled job to keep the dashboards current.
MeowlyBot is our Discord application (ID 1277779657630154804). It provides moderation, tickets, community games, and server administration inside Discord servers that have invited it. A server administrator invites it, and can remove it at any time. Everything in this section applies only inside servers where MeowlyBot is present.
MeowlyBot uses two privileged Discord gateway intents. What each one is for, and what we keep:
We receive member list and member update events for servers MeowlyBot is in. We use them to apply and audit roles, run join gates and verification, drive welcome and leave handling, keep moderation records attached to the right person after a name change, and detect ban evasion. We store the Discord user ID, current and previously observed usernames and display names, avatar hashes, server join date, role assignments, and moderation history (warnings, mutes, kicks, bans, and the moderator and reason for each). Discord does not offer a non-privileged way to receive member updates, so without this intent role auditing and evasion detection cannot work at all.
We read the text of messages sent in channels MeowlyBot can see. It is used for automated moderation (spam patterns, repeated messages, rate limits, blocked links, and AI-assisted review of borderline messages), text commands, custom reactions and auto-replies, keyword triage that routes messages needing a human to the moderation queue, channel rules such as media-only channels, message-based activity levels and experience points, moderation logs, ticket and modmail transcripts, community games such as counting. Discord offers no non-privileged way to read message text, and every one of those features operates on the text itself.
We retain message text in these cases:
Separately from the cases above, every message MeowlyBot can see is forwarded to our own operations server and kept for 90 days. That is described in "Forwarding to our operations server" below. Counts and derived signals — message length, link and attachment counts, activity timing — are stored on their own, without the message text.
MeowlyBot forwards what happens in a server — and the messages sent in it — to a private Discord server we own, with one channel for each server it is in. This is how we run the bot across every server at once: how we see what a server is doing, answer "why is the bot quiet here", and follow abuse that moves between servers.
It covers every server MeowlyBot is in, including ours. A server administrator can remove MeowlyBot at any time, which stops it — but they cannot leave the bot in and switch the forwarding off. A server's own list of channels excluded from its logs does not apply to this.
Direct messages you send to MeowlyBot are forwarded the same way. The first time you message it, it tells you so.
Only the platform owner and staff who hold an explicit permission grant can read these channels. Message text is deleted within 90 days. The record of what happened — who joined, who was warned, what changed — is kept for as long as the bot is in the server.
Whoever can manage your server in Discord — the server owner, anyone with the Administrator permission, or anyone with the Manage Server permission — can manage MeowlyBot's features in it from the manage page on our website. We do not issue a separate login for this, and we do not store a list of who administers which server: the question "may this person manage this server" is answered live from Discord's own permissions each time it is asked, and nothing about it is recorded. Removing someone from those permissions in Discord removes their access within about half a minute.
The manage page shows which of MeowlyBot's features are on in your server, and each one can be turned on or off with a switch. Changes apply immediately, and each change is recorded — with the account that made it and the change itself — in the same audit log that records the platform owner's own configuration changes.
Our team can turn a feature off for a specific server, and a feature turned off this way cannot be turned back on from the manage page; the page says so in plain words when it applies.
Asking for help from the manage page creates a support ticket in the MeowlyVA support server, and the ticket records which server the request came from.
Automated moderation sends the flagged message and its immediate context to a hosted AI moderation provider to score it. Only that message and context are sent, only when a message trips a detector, and the provider acts on our instructions and is not permitted to use the text for any other purpose.
MeowlyBot runs in more than one server, and the platform owner can look across them. Two things are meant by that, and they work differently: activity and messages are forwarded to our operations server as described above, and a look at anything else is recorded one item at a time. Section 6 sets out both.
Removing MeowlyBot from a server stops all collection for that server immediately. A server owner or administrator may request deletion of that server's stored data, and an individual member may request deletion of their own, by emailing [email protected] from an address we can tie to the account, or by contacting a MeowlyVA administrator. We action requests within 30 days. We may keep the minimum record needed to enforce a ban or to comply with law, and we will say so when we do.
These integrations are internal staff tooling. They connect accounts owned by MeowlyVA, are reachable only by authenticated team members holding the relevant permission grant, and are not available to visitors or community members. No personal data belonging to site visitors is sent to any of them.
youtube.readonly, youtube.force-ssl, yt-analytics.readonly, and yt-analytics-monetary.readonly. These scopes are used solely to fetch channel metadata, video metadata, performance metrics, monetization metrics, aggregated viewer demographics, and comment moderation data for the connected channel. We do not upload, modify, or delete any content on the connected channel under this flow. Tokens issued under this flow are stored server-side, encrypted at rest with AES, and accessed only by authenticated business-ops staff with two-factor authentication and the explicit business-ops-youtube permission grant.MeowlyVA staff may disconnect any of these accounts at any time from within the internal tools, and the owner of a connected account may revoke MeowlyVA's access from that platform's own settings. For the Business Operations Viewer flow, the owner of the connected YouTube channel may also revoke access at any time from their Google account permissions page. Revoking access stops further data collection but does not delete analytics snapshots already stored on our servers; for deletion of previously collected analytics data, please contact us via the channel listed below.
MeowlyVA's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use YouTube channel data, video metadata, analytics, monetization data, or videos uploaded through the publishing flow to serve advertisements, and we do not transfer this data to any third party except as strictly necessary to operate the dashboards described in this policy or to comply with applicable law.
MeowlyVA uses YouTube API Services. By using MeowlyVA, you agree to the YouTube Terms of Service and to the Google Privacy Policy.
We do not sell, trade, or rent your personal information to third parties. We do not share your data with any third party except:
Access across servers. MeowlyVA runs on more than one Discord server, and the platform owner can look at data from any of them. Two paths, and they are not the same. Activity and messages are forwarded continuously to our own operations server, described in section 3; that is ongoing, it is not recorded look by look, and a server cannot switch it off. Anything else — revealing a member's email or IP address, for example — is a separate deliberate act, recorded one record per item viewed with who did it, when, and the reason they wrote down. Neither is shared outside MeowlyVA. We do not notify a server when the second happens, because doing so would defeat the abuse and ban-evasion investigations it exists for.
Account data is retained as long as your account is active. You may request deletion of your account and associated data at any time.
For data collected under the MeowlyVA Business Operations Viewer flow, analytics snapshots (views, watch-time, revenue, demographics, etc.) and video metadata are retained for as long as the underlying YouTube channel remains connected, so that historical period-over-period comparisons remain available to the business operations team. If MeowlyVA disconnects a channel, or if the channel owner revokes access through Google, the stored OAuth tokens are deleted on the next reconciliation cycle and no further data is fetched. Previously stored analytics snapshots are retained for accounting and reporting continuity unless deletion is specifically requested via the contact channel below.
For MeowlyBot, moderation records and their stored evidence are retained while the bot remains in the server, because they are the history a moderator needs to act proportionately on a repeat offence. Ticket and modmail transcripts are retained for the life of the ticket and its archive. Messages forwarded to our operations server, including direct messages to the bot, are deleted after 90 days; the record of what happened in a server is kept for as long as the bot is in it. Removing MeowlyBot from a server stops all further collection for that server; stored data is deleted on request, as described in section 3.
We implement industry-standard security measures to protect your information. OAuth tokens for every internal integration described above — publishing and the Business Operations Viewer alike — are encrypted at rest using AES with a server-side encryption key managed outside the database. Sensitive credentials are never stored in plain text. Access to the internal tools is restricted by authenticated session, mandatory two-factor authentication, and an explicit per-section permission grant.
Our services are not directed to children under the age of 13. We do not knowingly collect personal information from children under 13. If you believe we have inadvertently collected such information, please contact us.
We may update this Privacy Policy from time to time. The date at the top of this page reflects the most recent revision. Continued use of our services constitutes acceptance of any updated policy.
For privacy questions or data deletion requests, email [email protected]. We reply within 30 days. You may also reach us through our Discord community or the MeowlyVA website, but email is the channel we monitor for these requests.