Privacy Policy
Who we are
ViralView (viralview.ai) is a creator-marketing platform connecting brands with football creators. This policy covers the viralview.ai website, app, and creator account connections.
What we collect
Account data: your name, email, and account type when you sign up.
Public creator data: publicly available profile and post statistics (follower counts, video views, likes, comments, captions) used to power discovery and campaign measurement.
Connected account data: if you connect a supported social account (Instagram, TikTok, YouTube, or a Facebook Page), we store an encrypted access token and the read-only analytics that account authorises — profile details, your own recent posts, and their performance — solely to report campaign performance you are part of. We request no permission to post, message, or change anything on your account.
Story insights: stories expose numbers no platform API provides, so where a campaign needs them we ask you to upload a screenshot of your own story insights and read the figures from it. That is separate from any connected account.
Campaign data: briefs, deals, deliverables, payments, and messages exchanged through the platform.
How we use it
To match brands with creators, price and track campaigns, report performance, and operate payments. We do not sell personal data.
Connected account data is used only for the features described in this policy: showing you your own performance, and reporting the performance of posts you delivered under a campaign to the brand that paid for that campaign. It is not used for advertising, and it is not used to train generalised AI or machine-learning models. Aggregated, non-identifying usage statistics help us operate the product; connected account data is not part of them.
Who we share it with
We do not sell personal data, and we never share it with advertisers or data brokers. We disclose it only to the following categories of recipient, each of which processes it on our instructions and may not use it for their own purposes:
Infrastructure providers who host the service under contract: Railway (application hosting) and Supabase (database).
Payment providers: Stripe, where a payment or creator payout is made.
AI service providers who generate the written analysis shown in the product, currently Google (Gemini). They process the data on our instructions and do not use it to train their models.
The brand that paid for a campaign you took part in — limited to the performance of the posts you delivered under that campaign.
Law enforcement or regulators, where we are legally required to disclose.
Google user data (YouTube)
If you connect your YouTube channel, then with your consent we receive the following through the YouTube Data API and the YouTube Analytics API: your channel's identity, the list of your own videos, and their performance — views, watch time, impressions, audience retention and audience demographics. We request read-only access. We ask for no permission to upload, edit, delete or comment, and we request no monetary or revenue scopes.
We use Google user data only to provide and improve the user-facing features described in this policy, and for no other purpose. We do not use it for advertising, we do not sell or transfer it, and we do not use it to train generalised AI or machine-learning models. We disclose it only to the recipients listed under "Who we share it with" above, or where required by law or to investigate a security incident.
We retain Google user data for as long as your channel is connected. Disconnecting deletes our copy of your tokens and stops all further collection; full account deletion is available at viralview.ai/data-deletion and is honoured within 30 days.
You can revoke ViralView's access to your Google account at any time at https://myaccount.google.com/permissions.
ViralView's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Our use of YouTube data is also governed by the YouTube Terms of Service (https://www.youtube.com/t/terms) and the Google Privacy Policy (https://policies.google.com/privacy).
Meta user data (Instagram and Facebook)
If you connect your Instagram professional account, then with your consent we receive the following through the Instagram API with Instagram Login: your account identity and profile details (instagram_business_basic), the list of your own media, and the insights for that media and account — reach, saves, shares, profile visits, average watch time and follower demographics (instagram_business_manage_insights). We request read-only access. We ask for no permission to publish, delete or edit content on your behalf.
If you connect a Facebook Page you manage, then with your consent we receive the list of Pages you manage (pages_show_list), the selected Page's profile and engagement fields (pages_read_engagement), that Page's own published posts (pages_read_user_content), and supported Page-post views and unique-viewer insights (read_insights). We do not read your personal Facebook feed, friends or messages. We request no permission to publish, delete or edit content on your behalf.
We use Meta user data only to provide the user-facing features described in this policy: showing you your own performance, and reporting the performance of posts you delivered under a campaign to the brand that paid for that campaign. We do not use it for advertising or ad targeting, we do not sell or transfer it, and we do not use it to train generalised AI or machine-learning models. We disclose it only to the recipients listed under "Who we share it with" above, or where required by law or to investigate a security incident.
We retain Meta user data for as long as your account is connected. Disconnecting deletes our copy of your tokens, asks Meta to revoke the grant, and stops all further collection. Full deletion is available at viralview.ai/data-deletion, which is also our registered data deletion callback, and is honoured within 30 days.
You can revoke ViralView's access at any time from your Instagram settings under Apps and websites, or from Facebook under Settings → Business integrations.
Our use of Instagram and Facebook Page data is governed by the Meta Platform Terms and Developer Policies.
TikTok user data
If you connect your TikTok account, then with your consent we receive the following through TikTok's Login Kit and Display API: your account identity, profile details and public statistics (user.info.basic, user.info.profile, user.info.stats), and the list of your own posts with their view, like, comment and share counts (video.list). We request read-only access. We ask for no permission to post, share or delete content on your behalf.
If you additionally connect TikTok's Business Account authorisation, then with your consent we use the read-only user.insights permission to receive the audience age, gender, country and city breakdowns available for your own TikTok account. We do not request permission to create or manage ads, audiences, messages, posts or account settings.
We use TikTok user data only to provide the user-facing features described in this policy: verifying that the account is yours, showing you your own performance, setting the fee our pricing model offers you, and reporting the performance of posts you delivered under a campaign to the brand that paid for that campaign. We do not use it for advertising, we do not sell or transfer it, and we do not use it to train generalised AI or machine-learning models. We disclose it only to the recipients listed under "Who we share it with" above, or where required by law or to investigate a security incident.
We retain TikTok user data for as long as your account is connected. Disconnecting deletes our copy of your tokens, asks TikTok to revoke the grant, and stops all further collection; full deletion is available at viralview.ai/data-deletion within 30 days.
You can revoke ViralView's access at any time in the TikTok app, under Settings and privacy → Security and permissions → Apps and services.
Storage and security
Data is stored with our hosting providers (Railway, Supabase) in encrypted-at-rest databases. OAuth tokens are additionally envelope-encrypted at the application layer. Access is restricted to the operating team.
Your rights and deletion
You can disconnect a linked social account at any time. We delete our copy of the access token and ask the platform to revoke the grant, so the permission stops appearing in your own TikTok, Google or Meta settings. If the platform doesn't confirm the revoke, you can always remove it there yourself. You can request full deletion of your account and associated data at any time — see viralview.ai/data-deletion for the process, or email hello@viralview.ai. Deletion requests are honoured within 30 days.
Contact
Questions: hello@viralview.ai. Last updated: 17 August 2026.