Last Updated: 22.07.2026
This Privacy Policy ("Policy") explains how ViralUp ("Company", "we", "our", or "us") collects, uses, and protects personal information from users ("Users") of the ViralUp AI application ("Application").
By downloading, accessing, or using the Application, you agree to the practices described in this Policy.
ViralUp AI is designed to minimize the collection of personal data. The Application may collect the following information:
No sensitive personal information such as identity numbers, payment card details, or precise location data is collected by the Application.
The collected data may be used for the following purposes:
The Application allows users to generate videos using artificial intelligence technologies.
User prompts, generation settings, and related data may be temporarily processed by AI systems to generate requested videos.
This data is used only for processing the requested generation task and improving service performance.
ViralUp AI does not sell or rent user personal data.
User data may be shared only in the following circumstances:
The Application relies on the following sub-processors to function. Each is listed with its purpose, hosting region, and the safeguard relied on for international transfers where applicable. ViralUp maintains a Data Processing Addendum (DPA) on file with each named processor or relies on the processor's standard Terms of Service where a DPA is not separately negotiated (as noted).
When a user opts in (Section 6) ViralUp also interacts with YouTube (Google LLC), TikTok for Developers, and Meta Graph API (Instagram) on behalf of the user. These are not sub-processors of ViralUp in the GDPR sense, but data controllers in their own right. See Section 6 for the OAuth-scoped data ViralUp accesses on the user's behalf.
All sub-processors operate under their own privacy policies. ViralUp maintains a Data Processor Register (see docs/processors-registry.md in our public repository) and updates this list when a sub-processor is added, replaced, or retired. Material changes are surfaced via the "Last Updated" date at the top of this page.
ViralUp lets users optionally connect their own social media accounts (YouTube, TikTok, Instagram) so that AI-generated videos can be published to those channels on the user's behalf. Connection is initiated by the user via OAuth and can be revoked at any time.
ViralUp's use of information received from YouTube APIs, and any other Google APIs, will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
When a user connects a YouTube channel, ViralUp accesses:
YouTube user data accessed through this integration is used only to display connected-channel information, to upload user-initiated content, and to show the user performance insights for their own content. ViralUp does not:
Storage and retention: OAuth refresh tokens for connected YouTube channels are stored encrypted at rest (AES-256-GCM) in our database. They are used to refresh access tokens for uploading videos the user has scheduled in ViralUp and for fetching performance insights for the user's own content. ViralUp stores YouTube authorization tokens only for as long as your YouTube account remains connected and in active use. Tokens are deleted immediately when you disconnect your YouTube account or delete your ViralUp account, and are automatically revoked and deleted after 180 days without use.
How to revoke access: Users can revoke ViralUp's access to their YouTube channel at any time via the Google Permissions page or the "Disconnect" button on the ViralUp Settings > Social Accounts page. Upon revocation, ViralUp deletes the stored access tokens and channel metadata. Videos already uploaded to YouTube are not affected and remain owned by the user on their channel.
Use of the YouTube integration is additionally subject to the YouTube Terms of Service. In addition to ViralUp's own privacy practices, Google's handling of your data is governed by the Google Privacy Policy.
When a user connects a TikTok account, ViralUp accesses the user's display name and avatar (for dashboard display), the permission to publish videos on the user's behalf, and read-only access to the account's public statistics (follower, like, and video counts) and video list (per-video view, like, comment, and share counts) to show performance insights (scopes: user.info.basic, user.info.stats, video.publish, video.upload, video.list). OAuth tokens are stored encrypted at rest. Revoke access via TikTok account settings or the "Disconnect" button in ViralUp.
When a user connects an Instagram account (Business or Creator account, linked to a Facebook Page), ViralUp accesses the linked Instagram username, avatar, and the permission to publish content on the user's behalf via the Meta Graph API. OAuth tokens are stored encrypted at rest. Revoke access via Meta Business Settings or the "Disconnect" button in ViralUp.
Personal data is retained only as long as necessary to provide the services of the Application.
If a user deletes their account or requests deletion, associated personal data will be removed unless retention is required by law.
Generated AI content may be stored temporarily for processing and service improvement.
Users have the following rights regarding their personal data:
Your right to erasure (GDPR Article 17): You can request the deletion of your account and associated personal data by clicking "Delete account" in Settings. Your account is marked for deletion immediately, with a 7-day undo window. Any active subscription is set to cancel and is terminated when the deletion executes; remaining paid time is not refunded. After the grace period, we automatically delete your data from Firebase Authentication, our databases and file storage, revoke the access our app holds to any connected social accounts, and delete your product analytics profile (PostHog). Measurement signals shared with our advertising partners (Meta, TikTok) consist of hashed event data only; we do not upload audience lists, and once transmitted these platforms process that data as independent data controllers under their own terms, so you can also exercise your rights directly with them. Our web analytics (Google Analytics) and error telemetry (Sentry) are configured without names, email addresses, or other direct identifiers (a pseudonymous ID only) and are deleted automatically at the end of their retention windows. If you submit an explicit personal data erasure request (in addition to, or instead of, routine account deletion), we will also forward corresponding deletion requests to these platforms on your behalf. Billing records at our payment providers are retained in anonymized form for tax-law compliance per GDPR Article 17(3)(e); transactional email delivery logs are retained by our email sub-processor under its data-processing agreement. Total SLA: 30 days from your request per GDPR Article 12(3).
Users may also exercise these rights by contacting: contact@viralup.ai
ViralUp uses commercially reasonable security measures to protect user data. However, no method of transmission or storage over the internet can be guaranteed to be completely secure.
Users acknowledge this risk when using the Application.
ViralUp AI is not intended for individuals under the age of 13.
We do not knowingly collect personal information from children under 13. If such data is discovered, it will be deleted promptly.
This Privacy Policy may be updated periodically to reflect changes in the Application or legal requirements.
Updates will be published within the Application or on the relevant distribution platform.
Continued use of the Application after updates constitutes acceptance of the revised Policy.
For any questions regarding this Privacy Policy, please contact:
ViralUp
Email: contact@viralup.ai