Back to creator workspace VIRALDNA · LEGAL & PRIVACY

Privacy Policy

1. Who operates ViralDNA

ViralDNA is the service brand. The operator and privacy contact appear in the contact panel on this page. Those details must be completed before public launch.

2. Information you provide

Your creator profile includes your niche, intended audience, goal and optional offer. Tracked creator references, profile preferences, saved hooks, filming briefs and any manually entered performance results are stored in this browser’s local storage. They remain until you remove them or clear browser storage. When account sign-in is configured, you can explicitly save this workspace to your account and restore it on another device. Cloud saves include the profile, tracked references and saved ideas/results; public competitor counts are not part of that workspace payload. Cloud workspace save is optional and is not automatic. Separately, signed-in research requests automatically store the selected creator and video identifiers on the server to enforce plan limits and identify which cached results your account can access.

If account sign-in is configured, Supabase processes your email address, authentication and session information. A selected checkout Price ID may be remembered on this device for up to 30 minutes to preserve your billing choice across an emailed sign-in link. It grants no paid access. Necessary session tokens may be stored in this browser by its SDK. The API verifies your session; it does not accept a user identifier supplied as proof of identity. We retain account identifiers, subscription references, monthly usage and refund records, trial eligibility and checkout-session references, research-access grants and server-side tracked-creator identifiers to operate paid access and prevent abuse. These records require an account-deletion request through the operator contact; the local-data deletion control does not delete your account.

When you request live generation or personalization, the relevant topic, angle, profile, offer and selected analysis are sent to our API and AI provider to produce the result. Do not submit passwords, payment-card information, sensitive personal data, confidential client details, or another person’s non-public information.

3. Public creator information

The working public YouTube, Instagram and TikTok integrations collect creator identifiers, names, descriptions, thumbnails, video identifiers, publication times, duration, available view/play/like/comment/share counts and playback availability. Public content can contain personal information; public availability does not remove privacy rights.

AI processing may produce opening quotes, timestamped observations, topic and hook classifications, CTA wording, structure and suggested adaptations. These integrations do not require your Instagram or TikTok login. We do not collect private retention, reach, saves, buyer identities or sales analytics through public-profile research. Unavailable metrics are not inferred. Manually entered business results are supplied by you, not verified platform data.

4. Why we process it

We use these inputs to collect requested public examples, analyze videos, generate original suggestions, personalize briefs, save your local workflow, prevent duplicate processing, handle errors and protect service availability. Shared video analysis may be reused for other users requesting the same public video. Personalized outputs are cached separately using a key derived from the analysis and profile.

With optional measurement consent, we store a random browser identifier and bounded public campaign labels to measure visits and button actions. The identifier expires after 90 days. We do not store full referrer URLs, emails, creator handles, topics, authentication tokens or payment-card details in visit measurement. If Meta measurement is configured, Meta receives the permitted visit and button events after consent. Rejecting or withdrawing consent stops future optional measurement and clears this device’s measurement identifier. Previously collected records expire through periodic cleanup within 90 days of collection. Verified account creation, completed first analyses, trials, paid invoices and processing budgets are also counted to operate and assess our service; financial records do not depend on optional advertising consent. We do not sell personal information or train our own AI models on your inputs. Third-party providers operate under their own applicable terms and privacy practices; we do not promise that they perform no logging or retention.

5. Providers and external content

YouTube/Google processes public-data requests, thumbnails and embedded playback. Gemini/Google processes media and relevant text for AI analysis or generation. The Gemini integration disables request storage where supported, which does not override provider policies. Instagram/TikTok thumbnails and avatars are retrieved through authenticated server endpoints with bounded temporary memory caches. Direct requests to YouTube thumbnail hosts can disclose your IP address and standard browser request information; YouTube embedded playback connects to YouTube and may use its storage or cookies. Instagram and TikTok source media may be retrieved through our server for playback and analysis; opening original-post links connects to those platforms.

If billing is configured, Stripe processes checkout, payment and subscription information. ViralDNA stores payment-provider customer/subscription identifiers and subscription status, and provides a link to Stripe’s billing portal. We do not receive or store full payment-card details. Account sign-in and billing are unavailable when their providers are not configured.

Apify and its selected collectors process requested public Instagram and TikTok profile usernames or post URLs and return public profiles, posts, metrics and media pointers. TikTok collection uses the collector’s video-download option so source media can be supplied to Gemini and played. Apify retains datasets and temporary media according to its account retention settings and provider policies. ViralDNA keeps collected feed metadata for up to 12 hours and retained research for up to 30 days; source video bytes are held temporarily in server memory, not saved as a permanent ViralDNA video library. We discard returned comment text and related-profile lists from our stored collection data. If optional Meta ad measurement is configured and you consent, Meta receives page and button events using its Pixel and may use cookies or similar identifiers. We do not supply account email, niche, researched creator handles or filming-brief text to this integration. Automatic advanced matching is disabled. Rejecting optional measurement does not limit app access; change your choice using Ad privacy settings on the landing page. Network identifiers and page information may still be processed by Meta under its policies. Do not include sensitive information in public landing-page URLs. ElevenLabs Scribe and Perplexity remain unconnected. Links to external websites take you to services governed by their own policies.

6. Storage, retention and security

Public metadata is cached with an expiry; YouTube channel metadata normally expires after 15 minutes; social feed metadata is cached for up to 12 hours. Successful shared analysis, creator-request snapshots and personalized-output cache entries expire after up to 30 days under the current configuration. Cleanup runs periodically, so expiry and physical deletion need not occur at the same instant. Local browser records have no automatic expiry. If you choose cloud save, account workspace records remain until you delete the cloud workspace or make an applicable deletion request. Account usage and billing references are retained as needed for service, accounting and legal obligations; invoice and subscription records may be retained for up to seven years where required for accounting, disputes or legal obligations. Workspace and research-access records remain while your account is active, subject to the cache limits described above. Verified deletion requests are reviewed before records are erased or retained under an applicable exception. Optional visit records and AI cost/operational alert details are removed after 90 days by periodic cleanup.

The API receives network identifiers as part of normal HTTP operation and uses in-memory request-rate counters. Railway hosts the application and Supabase provides authentication and database storage. They may keep infrastructure and access logs under their own policies. We avoid logging creator inputs, authentication tokens and payment credentials in our application logs. Information may be processed outside your country by providers.

We use measures such as server-side API keys, input validation, access restrictions where configured, and bounded retention. No service or browser storage is completely secure. Export important briefs, avoid sensitive inputs and protect devices that store your workspace.

7. Your choices and requests

You can edit your profile, remove tracked creators, delete saved ideas, download individual filming briefs, or clear all ViralDNA browser records using the control below. Signed-in users can separately delete the cloud workspace using the account workspace controls. Clearing local data does not erase cached public-video analysis or records held by external providers.

Use the privacy contact for questions or legally applicable access, correction, objection or deletion requests, including concerns about public creator information. We may need proportionate information to verify a request. Applicable rights and exceptions depend on your location; this policy does not reduce mandatory rights. Signed-in users can download their own account records and submit a verified deletion request from My account. Cancel any paid subscription first, and contact the operator using your request reference. A deletion request does not immediately erase the account; support verifies and processes it and explains any records that must be retained.

8. Age and changes

ViralDNA is intended for adults aged 18 or older. Do not submit children’s personal information. We may update this policy as functionality changes and will show the current version here. Material new processing should be explained before it begins.

Clear this device’s ViralDNA data

This deletes the local creator profile, watchlist, niche preference and saved ideas. Download important filming briefs first. It does not delete public-video server caches or external-provider records.