FR · EN
Diwaller

Privacy Policy

Last updated: 2026-07-13

This policy describes how LARA CHRISTOPHER ("we"), operator of the Diwaller service available at https://diwaller.app, processes personal data of its users and of third parties whose content is moderated through the application.

1. Data controller

  • LARA CHRISTOPHER
  • 2 B impasse du Point du Jour, 69005 Lyon, France (EU)
  • SIREN: 918 439 944 — SIRET (head office): 918 439 944 00029
  • Contact: [email protected]

2. Data we collect

Account data (Diwaller user)

  • Business email and brand/channel name entered at signup.
  • Password stored as a bcrypt hash (cost 12).
  • TOTP secret and recovery backup codes (bcrypt-hashed) for two-factor authentication.
  • Last-login timestamp, failed-attempt counters.

OAuth data from connected platforms

When you connect a YouTube, Facebook, Instagram, or TikTok account:

  • Account/channel identifier and public name.
  • OAuth tokens (access_token, refresh_token) encrypted at rest using Fernet (AES-128-CBC + HMAC).
  • Scopes granted.
  • Your own OAuth client credentials (Bring-Your-Own-OAuth-App model), encrypted at rest.

Moderation data

  • Comments retrieved via the platforms' official APIs for analysis and moderation.
  • Comment authors (identifier and public name as returned by the platform).
  • Moderation decisions (keep, delete, hide, reply) and action logs.

Technical data

  • IP address and User-Agent for rate limiting, abuse prevention, and audit.
  • Session cookies (diwaller_session signed JWT, csrf_token anti-CSRF) — strictly necessary.
  • Server logs (URL, HTTP status, timestamp) — kept for 30 days.

3. YouTube API Services

Diwaller uses the YouTube API Services to provide its YouTube-related features: retrieving and moderating comments posted on your videos, replying to comments, and channel/video statistics (subscribers, views). By connecting a YouTube channel to Diwaller, you agree to the YouTube Terms of Service. Google's handling of that data is governed by the Google Privacy Policy (https://policies.google.com/privacy).

  • Data processed: comments posted on the connected channel's videos (text, author public identifier and name, timestamp) and statistics of the channel and its videos (subscribers, views, likes). Diwaller only accesses channels explicitly connected by their owner through Google OAuth — never data from third-party channels.
  • Revocation: you can revoke Diwaller's access to your YouTube data at any time, either by disconnecting the channel from Diwaller or via the Google security settings page: https://myaccount.google.com/permissions.
  • Deletion: disconnecting a channel or deleting your account deletes the OAuth tokens and the stored YouTube data (comments, statistics) within 30 days — see our data deletion procedure.
  • YouTube data is never sold, shared with third parties for advertising purposes, or used for competitive analytics.

4. Purposes and legal bases (GDPR)

  • Providing the service (automated moderation, dashboard) — performance of contract (Art. 6(1)(b) GDPR).
  • Authentication and security (mandatory TOTP, rate limiting, audit) — legitimate interest (Art. 6(1)(f)).
  • Connecting third-party platforms — explicit consent via the OAuth flow (Art. 6(1)(a)).
  • Improving the service via AI classification — legitimate interest; we do not train models on your data.

5. Recipients

Your data is processed solely by LARA CHRISTOPHER. We use the following technical sub-processors, all established in or compliant with the GDPR:

  • Contabo GmbH (Germany, EU) — hosting the application server and the PostgreSQL database.
  • Cloudflare, Inc. — CDN, WAF, and ingress tunnel (Cloudflare Tunnel). Cloudflare is certified under the Standard Contractual Clauses and the Data Privacy Framework.

No data is sold or shared for advertising purposes.

6. Transfers outside the EU

Application data (account, encrypted tokens, moderated comments) is stored in Germany (EU). Cloudflare may handle traffic in transit via its global points of presence; such transfer is governed by the Standard Contractual Clauses of the European Commission.

7. Retention

  • Account data: for the duration of use, deleted within 30 days after account deletion.
  • OAuth tokens: until revoked by you or expired by the platform.
  • Moderated comments: 12 rolling months by default, configurable.
  • Audit logs (actions_log, db_admin_audit): 12 months.
  • Server logs (uvicorn, loguru): 30 days.

8. Your rights

Under the GDPR, you have the following rights:

  • Access to your personal data.
  • Rectification of inaccurate data.
  • Erasure ("right to be forgotten").
  • Restriction of processing.
  • Portability of your data in a machine-readable format.
  • Objection to processing based on legitimate interest.
  • Withdrawal of consent at any time (disconnecting a platform).

To exercise these rights, write to [email protected]. We respond within 30 days. You may also lodge a complaint with the French data protection authority (CNIL, www.cnil.fr).

9. Security

  • Passwords: bcrypt (cost 12).
  • Mandatory TOTP 2FA for owner/admin roles.
  • OAuth tokens encrypted at rest (Fernet, rotatable keys).
  • JWT HS256 sessions, HttpOnly + Secure + SameSite=Lax cookies.
  • Security headers: HSTS, CSP, X-Frame-Options DENY.
  • CSRF protection (double-submit token).
  • Strict multi-tenant isolation (P1) enforced on every request.
  • Encrypted backups and retained audit logs.

10. Cookies

Diwaller uses only strictly necessary cookies (authentication, anti-CSRF, time-range persistence). No third-party advertising or behavioural-tracking cookies are set.

11. Changes

We may amend this policy to reflect technical or legal changes. Any material change will be notified by email. The current version is always available at /privacy/en.

© 2026 LARA CHRISTOPHER · Confidentialité · Conditions · Mentions légales · Se connecter