Privacy

Privacy Notice

This notice explains what Toxly processes, why it is processed, how long it is stored, and what rights users and customers have.

Last updated: August 12, 2026

Controller and contact

Toxly is operated by Jamie Kern under the Toxly product name. Privacy and account requests can be sent to privacy@toxly.net or submitted through the help center.

When Toxly moderates content on behalf of a customer, the customer is usually the controller for its end-user content and Toxly processes that data as a processor under the customer's instructions.

  • Privacy contact: privacy@toxly.net
  • Help center: https://toxly.net/help

Account, API, Discord, support, and billing data

Toxly processes account details, authentication data, project settings, API key metadata, moderation inputs during the request, short text previews, hashes, category scores, decisions, Discord IDs and settings, support messages, and Stripe billing references depending on the features enabled.

Full submitted text is used to create a moderation decision. Long-term moderation logs are designed to store a short preview of up to 200 characters and a hash, not the full original text.

  • OpenAI may receive content when OpenAI moderation or support AI is enabled.
  • Livecristen Mail API is used for transactional email.
  • Stripe is used for checkout, subscriptions, invoices, and billing portal access.
  • Discord is used for OAuth and bot moderation.
  • Cloudflare Turnstile may be used for bot protection.

Retention

Moderation logs including text previews are stored for 30 days. Rate-limit and abuse signals may be stored for up to 90 days. Repeat moderation decisions may be stored permanently as keyed hashes with scores, categories, and reason, without storing the full original text. The current project policy still decides the final action. Security and login logs are stored for 90 days. Audit logs are stored for 12 months.

Support tickets are stored for 24 months after closure. Billing and tax records may be stored for up to 10 years. Rolling backups are kept for up to 30 days.

Rights and transfers

Users may request access, correction, deletion, restriction, portability, objection, and withdrawal of consent. Users also have the right to lodge a complaint with a data protection authority.

Some providers such as OpenAI, Stripe, Discord, or Cloudflare may process data outside the EU/EEA. Where required, transfers are supported by appropriate safeguards such as standard contractual clauses, Data Privacy Framework certifications, or comparable mechanisms.

Automated decisions

Toxly returns technical moderation decisions and risk scores. Toxly itself does not make legally binding decisions about end users; customers decide how to use these signals in their own products.