Effective September 15, 2026
Privacy Policy
This policy explains the information Viraal processes when you visit our website, create an account, connect services, or create content with the product.
Information we process
- Account and profile information, including your name, email address, and authentication identifiers.
- Workspace information you provide, such as business names, websites, logos, audiences, offers, and brand preferences.
- Content and media you upload, create, edit, or export through Viraal.
- Billing and subscription status. Payment-card details are processed by our payment provider rather than stored directly by Viraal.
- Connection information for social platforms you choose to link, including provider account identifiers, granted permissions/scopes, and encrypted OAuth access and refresh credentials stored on our servers.
- Publication metadata such as captions, destination settings, schedules, and provider post identifiers needed to publish and reconcile status.
- Technical and usage information such as device, browser, IP address, pages viewed, feature interactions, errors, and performance data.
How we use information
- Provide, secure, maintain, and improve the service.
- Generate and personalize content using the workspace context you supply.
- Authenticate accounts, process subscriptions, and provide customer support.
- Connect social accounts you authorize and publish content you explicitly submit to those platforms.
- Monitor reliability, prevent abuse, enforce usage limits, and troubleshoot errors.
- Communicate service, security, billing, and product updates.
Google / YouTube
When you connect YouTube, Viraal uses Google OAuth to obtain authorization for the scopes required to list your channels and upload videos (currently YouTube readonly and upload scopes). We receive channel identifiers and profile display information needed to show the connected channel (such as channel title, custom URL/username, avatar URL, and basic channel statistics returned by YouTube), and we store encrypted OAuth access and refresh tokens, granted scopes, and token expiry metadata on our servers so we can upload on your behalf when you publish.
We use Google user data only to provide or improve user-facing YouTube connection and publishing features you initiate in Viraal (Limited Use). We do not sell Google user data, and we do not transfer or disclose Google user data for targeted advertising, personalized advertising, retargeting, data brokerage, information resale, creditworthiness determinations, or lending.
Sharing, transfer, and disclosure of Google user data: (1) Google / YouTube — when you connect or publish, Viraal communicates with Google’s and YouTube’s APIs as needed to exchange OAuth tokens, retrieve channel information you authorize, refresh credentials, revoke access on disconnect, and upload the media/captions/destination settings you submit. (2) Service providers / processors — Google user data (including encrypted OAuth credentials and connection metadata stored in our application database) may be processed by infrastructure providers that host, store, secure, or maintain Viraal on our behalf (for example application hosting and managed database services). Those providers process data only to operate the service for us, not for their own advertising purposes. (3) Legal / security — we may disclose information where required by applicable law or legal process, or where necessary to investigate fraud, abuse, or security incidents. We do not send Google OAuth access tokens, refresh tokens, or authorization codes to analytics, advertising, or unrelated third-party marketing systems, and we do not expose those credentials to client-side JavaScript APIs used for product analytics.
AI / machine learning: Google user data obtained through Google APIs (including YouTube channel identifiers, channel metadata, and OAuth credentials) is not used as input to Viraal’s AI content-generation features and is not transferred or used to train generalized AI or machine-learning models. AI features use workspace and content context you supply in Viraal, which is separate from Google API user data.
You can disconnect YouTube in Settings → Integrations; Viraal then attempts to revoke the Google token and deletes stored credentials for that connection. You may also remove access from your Google Account settings.
Meta / Instagram
When you connect Instagram, Viraal uses Meta Facebook Login for Business / Graph APIs to discover Facebook Pages linked to Instagram professional accounts and to publish Reels, feed images, or carousels you choose. We process Page and Instagram account identifiers, usernames, and related connection metadata, plus encrypted Page/user tokens required for publishing.
Platform Data from Meta is used only to provide Instagram connection and publishing. When Meta sends a deauthorization or data-deletion callback, or when you disconnect Instagram in Settings, Viraal disconnects matching connections and clears related encrypted credentials and provider profile metadata for those links. See our Data Deletion instructions for user-facing steps and Meta deletion request handling.
TikTok
When you connect TikTok, Viraal uses TikTok Login Kit to obtain basic account identity (such as open_id and display name) and authorization to publish via the Content Posting API (Direct Post) when enabled for your environment. We store encrypted OAuth tokens and creator capability snapshots needed to show privacy and interaction options and to post only after you confirm destination settings.
Unaudited TikTok clients may be limited to private (SELF_ONLY) visibility until TikTok audit approval. Disconnecting TikTok in Settings clears local encrypted credentials for that connection.
Service providers and connected platforms
Viraal relies on service providers for hosting, object storage, authentication, analytics, email, payments, media processing, and AI-assisted generation. We share information with them only as needed to operate the service. When you connect a third-party social platform (Google/YouTube, Meta/Instagram, or TikTok), that platform’s terms and privacy policy also apply, and media/captions you choose to publish are transferred to that platform’s APIs. Additional detail on how Google user data is shared or disclosed is described in the Google / YouTube section above.
Product analytics and session replay
We use PostHog to understand navigation, signup and onboarding completion, content-generation and export outcomes, and product performance. Analytics associate activity with an account identifier after sign-in. We also use masked session replay to understand interactions and troubleshoot usability problems. Replay preserves public page text and styling, masks private page and dialog text and all form inputs, and blocks media elements; our configuration does not record request bodies, request headers, or console logs. We do not send email addresses, verification codes, passwords, prompts, or generated copy as custom analytics properties.
Retention and security
We retain information for as long as needed to provide the service, meet legal and accounting obligations, resolve disputes, and protect the service. Retention can vary by data type and account status. Encrypted social credentials are retained while a connection remains active and are removed or invalidated when you disconnect or when a provider deletion/deauthorization request is processed. We use administrative and technical safeguards designed to protect information, but no online service can guarantee absolute security.
Your choices and requests
You may disconnect social accounts in product settings. You may ask to access, correct, export, or delete personal information, or object to certain processing, by emailing support@getviraal.io. Available rights depend on where you live. We may need to verify your identity before completing a request. Step-by-step deletion guidance is also published at /data-deletion.
Children and changes
Viraal is not directed to children under 13. We may update this policy as the product or applicable requirements change. We will update the effective date and provide additional notice when a change is material.
Contact
Privacy questions and requests can be sent to support@getviraal.io.