We use necessary cookies to run the service. Optional categories remain off unless you choose otherwise. Cookie Policy
Skip to main content
LC Shepherd
Sort Pens Train Settings
Draft — counsel sign-off is required before public launch.
Version: 2026-08-31.1 Effective: 2026-08-31 (draft)

Privacy Policy

DRAFT — counsel sign-off required before public launch. ⚠️ This document must be reviewed by a qualified data-protection lawyer before it is published. It states what the product actually does in plain language so counsel can verify and finalise it — accuracy of the described flows is engineering-verified; the legal sufficiency is not yet.

Version: 2026-08-31.1 Effective: 2026-08-31 (draft)

This policy explains how Little Collie Shepherd ("LCS", "we") handles personal data when you use our comment-moderation service (the "Service"). It covers two very different relationships, and it is honest about the difference:

  1. Your data — account, billing, and usage data about you and your team, which we process as a controller. That is what most of this policy is about.
  2. Your commenters' data — the comments and commenter details from the channels and sites you connect, which we process on your instructions as a processor. That relationship is governed by the Data Processing Agreement (DPA) between you and us; section 6 below summarises it in plain language.

1. Who we are

LCS is the provider of the Service. (Counsel/owner: legal entity name, registered address, and — if required — EU representative and supervisory authority to be inserted before launch.) Contact: privacy@littlecollie.com (to be confirmed before launch).

2. What we collect about you

  • Account data: your name (if given), email address, and a hash of your password (never the password itself). If you sign in with a passkey, we store the passkey's public key — this cannot be used to identify you elsewhere.
  • Workspace data: workspace name, team memberships and roles, the settings and moderation policies you configure, and the record of which Terms of Service version your workspace accepted and when.
  • Billing data: your plan, invoices, and payment state. Card details are entered directly with our payment processor (Stripe); we never see or store full card numbers.
  • Usage and security data: sign-in events, action logs (who did what in the workspace), and technical logs needed to run and secure the Service.

We do not buy data about you, and we do not use advertising trackers.

3. Why we process it (legal bases)

  • To provide the Service — operating your workspace, moderating your connected sources on your instructions, support (contract, Art 6(1)(b) GDPR).
  • To bill you (contract; legal obligation for tax/accounting records).
  • To secure the Service — authentication, abuse prevention, audit logs (legitimate interest, Art 6(1)(f), in keeping the Service safe for all customers).
  • To tell you things that matter — service, security, and billing notices (contract). Anything promotional is opt-in.

4. How long we keep it

Account and workspace data are kept while your workspace is active. After termination we provide an export window and then delete workspace data on a fixed schedule; billing records are retained as long as tax and accounting law requires.

Records about commenters do not wait for your workspace to close. Comment content, commenter names and profiles, the reasons recorded against a moderation decision, and the notes attached to your allow, watch and deny list entries are automatically redacted 24 months after they were last relevant, even while your workspace is open and active. You can choose a shorter period for your own workspace; you cannot choose a longer one. Two things deliberately survive: your moderation rules themselves, so an expired record never quietly stops protecting you from someone who comes back; and comments assessed as credible threats, which we keep for 6 years so that someone who was targeted still has the evidence if they need it.

(Counsel to confirm the committed windows; the operational schedule is defined in our offboarding process.)

Requests from law enforcement

Sometimes an authority asks for data rather than a person. We publish what we require, what we hold, and what we commit to telling you: see our Law-Enforcement Request Policy. The short version is that we require valid legal process, we produce the minimum responsive to it, and we tell the affected customer wherever we are legally permitted to.

5. Who else touches it

We use a small number of service providers (sub-processors) to run the Service — payment processing (Stripe), hosting, email delivery, and the AI provider that powers comment classification and the Rule Workshop (Anthropic PBC, United States). Each is bound by contract to process data only on our instructions. The current list is available on request and maintained with our compliance records, and we give notice before adding or changing a sub-processor.

6. Your commenters' data — the plain-language version

When you connect a YouTube channel or WordPress site, LCS processes the comments on it — including commenter names, IDs, and comment text — on your behalf and on your instructions. In that processing you are the controller and LCS is the processor; the DPA between us governs it, including security, sub-processing, assistance with data-subject rights, and deletion. Ask us for the DPA at any time.

Two design facts worth stating plainly, because they are what most people actually want to know about an automated moderation service.

What we send to classify a comment. Automated moderation sends the comment to an AI model operated by Anthropic PBC (United States). What we send is deliberately narrow: the comment text, the title and a short excerpt of the video or post it was left on, and — where the reply structure is available — the text of the comment it replies to. Optionally, and only if you have switched them on, a per-source "this content features people on camera" flag and a short, throwaway summary of recent activity on that source.

What we never send. We do not send the commenter's name, their channel or user id, their email address, their IP address, their avatar, or any score or reputation LCS has built up about them. The AI model is not told whose comment it is reading, and cannot be: our software refuses to send a request that carries any of those fields, and that refusal is a tested guarantee rather than a policy we ask our engineers to remember.

The provider is contractually barred from using anything we send to train its models, and we pin the exact model version we use so its behaviour cannot change underneath your moderation settings without us deciding to change it.

7. International transfers

  • Your data (account, billing, workspace) is processed where our infrastructure runs. (Hosting locations to be finalised with the infrastructure rollout; counsel to confirm transfer mechanics if any leg leaves the EEA/UK.)
  • Comment content and Anthropic (United States). The Service sends comment content to Anthropic PBC in the United States in two places, and nowhere else:

  • Automated moderation. Every comment that reaches the AI classification stage is sent, as described in section 6 — comment and context text only, with no commenter identity attached.

  • Rule Workshop. When a moderator in your workspace deliberately starts a Rule Workshop session (a human-initiated tool for drafting moderation rules), the comment examples that moderator chooses to work with are sent, to power the assistant in that session.

Both are covered by the DPA's transfer terms (see our international-transfers documentation; SCCs/DPF mechanics to be executed before launch). They are separate paths in our software with separate controls, and we describe them separately here because they are different in kind: the first is automatic and identity-free, the second happens only on a moderator's explicit action and carries whatever examples that moderator chose.

8. Your rights

You can access, correct, export, or delete your account data, object to or restrict processing, and complain to your supervisory authority. Write to the privacy contact above; we answer within the statutory deadlines. For commenter data on a connected source, we support you in answering your commenters' requests, as the DPA describes — commenters who contact us directly are pointed to the controller (you) and we assist as processor.

9. Cookies

We set only cookies that are necessary to run the Service (sign-in sessions and security), and none for advertising or cross-site tracking. The Cookie Policy lists every cookie by name, and the in-app consent control governs any optional category we may ever introduce — optional cookies stay off unless you turn them on.

10. Changes

We version this policy. Material changes are announced in-product and the version and effective date above always identify what you are reading.

Terms of Service Cookie Policy Law-Enforcement Requests
Terms of Service Privacy Policy Cookie Policy Law-Enforcement Requests Little Collie (opens in a new tab)