Privacy Policy

Who we are

ViralView AI, Inc. (ViralView, viralview.ai) operates a creator-marketing intelligence, campaign and marketplace service. This policy covers the website, app, public creator catalogue, campaign services and connected social accounts.

What we collect

Account data: your name, email, and account type when you sign up.

Public creator and content data: public profile identifiers, handles, biographies, profile images, account and audience counts, post URLs, captions, media, public engagement and performance statistics, publication dates and other information displayed publicly by a supported platform.

Derived creator and content analysis: classifications and recommendations generated from public content and performance, such as subject, format, opening, editing style, brand evidence, audience or market signals, estimated performance, commercial suitability, price estimates and the evidence, confidence, source and model version behind them. These are predictions and may be incomplete or wrong.

Face-resemblance data: when this collection lane is deliberately enabled, ViralView can derive a numerical face representation from a creator's current public profile picture and use it only to compare physical resemblance for an explicit look-alike request. The source profile picture remains the public catalogue image; we do not store a cropped face image. A reference photo uploaded for one search is processed in memory and is not persisted.

Connected account data: if you connect a supported social account (Instagram, TikTok, YouTube, or a Facebook Page), we store an encrypted access token and the read-only analytics that account authorises — profile details, your own recent posts, and their performance — solely to report campaign performance you are part of. We request no permission to post, message, or change anything on your account.

Story insights: stories expose numbers no platform API provides, so where a campaign needs them we ask you to upload a screenshot of your own story insights and read the figures from it. That is separate from any connected account.

Campaign and transaction data: briefs, creator recommendations, concepts, prices, deals, contracts, deliverables, reviews, campaign results, payments, payouts and messages exchanged through the platform.

Service and security data: IP address, device and browser information, authentication events, request and error logs, usage limits and records needed to prevent abuse and keep the service secure.

Where it comes from

We receive data directly from account holders and business customers; from official platform APIs when a creator connects an account; from public platform pages and media; and from service providers that collect or resolve publicly available creator and post information on our behalf, currently including ScrapeCreators.

Public availability does not remove a person's privacy rights. We record the platform identity, source and observation time so that information can be corrected, refreshed, restricted or removed where required.

How and why we use it

We use the information to discover and compare creators, understand what has performed for each creator, recommend creator-specific concepts, estimate prices and performance, operate campaigns and payments, verify delivery, measure results, prevent fraud and improve later recommendations.

For public business-facing creator data and derived analysis, our intended legal basis where applicable is our legitimate interest in providing creator-marketing intelligence and operating the marketplace, balanced against the creator's rights. For account, campaign and payment data, processing is generally needed to perform our contract, comply with law, secure the service or pursue our legitimate interests. Connected platform data is collected only after the account holder authorises the relevant read-only connection and remains subject to the platform's developer rules.

We do not sell OAuth tokens or private connected-account analytics. We charge customers for ViralView's software, recommendations and transaction services. Authorised customers can view public creator profiles and ViralView's derived recommendations inside the service.

Connected account data is used only for the user-facing and campaign features described here. It is not used for advertising, and it is not used to train a general-purpose AI model. Cross-campaign learning must use permissioned, appropriately aggregated information rather than exposing one customer's raw outcomes to another.

Who we share it with

We disclose information only as needed to operate the service, fulfil a campaign, comply with law or protect the service:

Infrastructure providers who host the service under contract: Railway (application hosting) and Supabase (database).

Payment providers: Stripe, where a payment or creator payout is made.

Public-data and media-resolution providers, currently ScrapeCreators. They receive the public handles, account URLs or post URLs required to fulfil a request.

AI service providers, currently Google (Gemini). Depending on the feature, selected public media, captions, metadata or a temporary source link may be sent to generate analysis. OAuth access tokens are not sent to the model. Under our paid API terms, submitted prompts and responses are not used to improve Google's products.

The brand that paid for a campaign you took part in — limited to the performance of the posts you delivered under that campaign.

Law enforcement or regulators, where we are legally required to disclose.

Automated analysis and its limits

ViralView uses automated models to classify content, estimate performance and price, and recommend creators and concepts. These outputs assist a campaign decision; they do not guarantee reach, sales or suitability. Customers and creators can ask us to correct source data or review a materially inaccurate recommendation.

A customer can explicitly ask for a physical look-alike or appearance criterion. ViralView may then use a local numerical comparison or, where that path is unavailable, send selected public profile images to Google solely for that requested comparison. We do not use this processing to establish or verify identity, and it is not a general identity-search service.

We do not rate attractiveness or a minor's appearance, and appearance evidence must not be presented as verified identity, ethnicity, health or another sensitive fact. Public content can include bystanders or people under 18, so missing or uncertain coverage is not a clean bill of health. A catalogue creator may request restriction, objection or deletion of appearance-based processing through the routes below.

Google user data (YouTube)

If you connect your YouTube channel, then with your consent we receive the following through the YouTube Data API and the YouTube Analytics API: your channel's identity, the list of your own videos, and their performance — views, watch time, impressions, audience retention and audience demographics. We request read-only access. We ask for no permission to upload, edit, delete or comment, and we request no monetary or revenue scopes.

We use Google user data only to provide and improve the user-facing features described in this policy, and for no other purpose. We do not use it for advertising, we do not sell or transfer it, and we do not use it to train generalised AI or machine-learning models. We disclose it only to the recipients listed under "Who we share it with" above, or where required by law or to investigate a security incident.

We retain Google user data for as long as your channel is connected. Disconnecting deletes our copy of your tokens and stops all further collection; full account deletion is available at viralview.ai/data-deletion and is honoured within 30 days.

You can revoke ViralView's access to your Google account at any time at https://myaccount.google.com/permissions.

ViralView's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Our use of YouTube data is also governed by the YouTube Terms of Service (https://www.youtube.com/t/terms) and the Google Privacy Policy (https://policies.google.com/privacy).

Meta user data (Instagram and Facebook)

If you connect your Instagram professional account, then with your consent we receive the following through the Instagram API with Instagram Login: your account identity and profile details (instagram_business_basic), the list of your own media, and the insights for that media and account — reach, saves, shares, profile visits, average watch time and follower demographics (instagram_business_manage_insights). We request read-only access. We ask for no permission to publish, delete or edit content on your behalf.

If you connect a Facebook Page you manage, then with your consent we receive the list of Pages you make available (pages_show_list), the selected Page's profile, own published content and engagement fields (pages_read_engagement), and supported Page-post views and unique-viewer insights (read_insights). We do not read your personal Facebook feed, friends, messages or user-generated Page content. We request no permission to publish, message, moderate, delete or edit content on your behalf.

We use Meta user data only to provide the user-facing features described in this policy: showing you your own performance, and reporting the performance of posts you delivered under a campaign to the brand that paid for that campaign. We do not use it for advertising or ad targeting, we do not sell or transfer it, and we do not use it to train generalised AI or machine-learning models. We disclose it only to the recipients listed under "Who we share it with" above, or where required by law or to investigate a security incident.

We retain Meta user data for as long as your account is connected. Disconnecting deletes our copy of your tokens, asks Meta to revoke the grant, and stops all further collection. Full deletion is available at viralview.ai/data-deletion, which is also our registered data deletion callback, and is honoured within 30 days.

You can revoke ViralView's access at any time from your Instagram settings under Apps and websites, or from Facebook under Settings → Business integrations.

Our use of Instagram and Facebook Page data is governed by the Meta Platform Terms and Developer Policies.

TikTok user data

If you connect your TikTok account, then with your consent we receive the following through TikTok's Login Kit and Display API: your account identity, profile details and public statistics (user.info.basic, user.info.profile, user.info.stats), and the list of your own posts with their view, like, comment and share counts (video.list). We request read-only access. We ask for no permission to post, share or delete content on your behalf.

If you additionally connect TikTok's Business Account authorisation, then with your consent we use the read-only user.insights permission to receive the audience age, gender, country and city breakdowns available for your own TikTok account. We do not request permission to create or manage ads, audiences, messages, posts or account settings.

We use TikTok user data only to provide the user-facing features described in this policy: verifying that the account is yours, showing you your own performance, setting the fee our pricing model offers you, and reporting the performance of posts you delivered under a campaign to the brand that paid for that campaign. We do not use it for advertising, we do not sell or transfer it, and we do not use it to train generalised AI or machine-learning models. We disclose it only to the recipients listed under "Who we share it with" above, or where required by law or to investigate a security incident.

We retain TikTok user data for as long as your account is connected. Disconnecting deletes our copy of your tokens, asks TikTok to revoke the grant, and stops all further collection; full deletion is available at viralview.ai/data-deletion within 30 days.

You can revoke ViralView's access at any time in the TikTok app, under Settings and privacy → Security and permissions → Apps and services.

Retention, storage and security

Data is stored with our hosting providers (Railway, Supabase) in encrypted-at-rest databases. OAuth tokens are additionally envelope-encrypted at the application layer. Access is restricted to the operating team.

Public platform identifiers, observations, captions, derived analysis and provenance may be retained while they remain needed for the catalogue, recommendations, accuracy, security or legal obligations. Temporary delivery URLs may be cached for processing and normally expire at the source. Source video files and working frames or audio are used for bounded processing and are deleted after that processing; they are not retained as catalogue media assets.

A stored face-resemblance vector is tied to the creator's current public profile picture and is cleared automatically when that picture changes or the creator is archived. Named public-figure reference vectors are an acceleration cache retained for no more than 30 days after refresh. Uploaded reference-photo bytes stay in memory for the request and are not retained.

Connected-account tokens and private analytics are retained while the account remains connected, subject to the platform-specific limits below. Campaign, contract, payment, dispute and tax records may be retained after account closure where law, fraud prevention or a live agreement requires it. We periodically review retention and remove or de-identify information that is no longer needed.

WhatsApp and SMS transport receipts—including phone numbers and message bodies—are retained for no more than 30 days for session handling, replay protection and delivery reconciliation. Deleting a linked account removes its transport receipts immediately. Creator questions that form part of a campaign conversation are also stored in that campaign's private message thread and follow the campaign-record rules above.

ViralView and its providers may process information in the United States and other countries. Where data-protection law requires it, we rely on an approved transfer mechanism and contractual safeguards.

Your rights and deletion

You can disconnect a linked social account at any time. We delete our copy of the access token and ask the platform to revoke the grant. If the platform does not confirm revocation, you can also remove ViralView in that platform's settings.

Account holders and people included in the public creator catalogue can ask what ViralView holds about them and request correction, restriction, objection or deletion where applicable. See viralview.ai/data-deletion or email hello@viralview.ai with the relevant platform handle or profile URL. We may need to verify that you control the account. We respond within the period required by applicable law, normally 30 days.

Some rights depend on jurisdiction and are not absolute. We will explain any information we must retain for an active contract, payment, legal claim, security record or other lawful reason. A catalogue creator may object to profiling even if they never created a ViralView account.

Contact

Questions and privacy requests: hello@viralview.ai. Last updated: 26 August 2026.