Privacy policy overview

Privacy Policy

ViralShort is designed to keep operator data minimal while supporting accounts, generated assets, workflow execution, publishing, and content operations.

Last updated: July 22, 2026

Minimal Collection

We collect the information required to run accounts, workflows, and publishing operations.

Secure Transport

Data moves over HTTPS, credentials are handled through managed providers, and assets are stored in controlled infrastructure.

Workflow Scope

Generated assets, prompts, metadata, and publish records may be stored to support automation, retries, and auditability.

Introduction

ViralShort (“we”, “our”, or “us”) is a workflow system for generating and publishing automated video content. We are committed to protecting the privacy of operators, collaborators, and end users whose data may pass through the platform.

Information We Collect

We collect the information necessary to provide and operate the service:

  • Account information: Email address, display name, and authentication metadata.
  • Workflow data: Prompts, generated assets, subtitles, metadata, publish records, and job execution history.
  • Device and session information: Browser, platform, and technical data required for compatibility and security.
  • Billing information: Subscription or payment data handled by our payment providers. We do not store full card numbers.

How We Use Your Information

  • To provide and improve workflow automation and publishing features
  • To save prompts, outputs, and settings associated with your projects
  • To process payments and subscriptions where applicable
  • To provide support and investigate failures or abuse
  • To send service-related notifications and product updates

Generated Content

ViralShort stores prompts, generated media, subtitles, and publishing metadata to support production, retries, moderation, and history auditing. We do not sell generated content or account data to advertisers.

YouTube API Services

ViralShort uses YouTube API Servicesto publish videos to YouTube channels that our users own and operate. When a user connects a YouTube channel, we request OAuth authorization and store the resulting access and refresh tokens solely to upload videos and manage their metadata (titles, descriptions, tags, thumbnails, and privacy status) on that user’s own channels. We do not use YouTube API Services to collect or analyze data from channels our users do not control.

By using ViralShort you also agree to the YouTube Terms of Service. Data we obtain through YouTube API Services is handled in accordance with the Google Privacy Policy.

You can revoke ViralShort’s access to your YouTube account at any time. Disconnect the channel from within ViralShort, or remove ViralShort’s access through the Google security settings page at https://security.google.com/settings/security/permissions. When access is revoked, we stop using the associated tokens and delete them from active systems.

TikTok Login Kit and Content Posting API

ViralShort uses TikTok Login Kit so a workspace administrator can connect a TikTok account they control. We request user.info.basic to identify the authorized account and video.publish for creator-approved direct posting. ViralShort never accesses unrelated TikTok accounts or videos.

Every TikTok video enters a review queue. Before any publish API call, the user sees the 9:16 video, editable caption, destination account, current privacy options, interaction controls, AI-content notice, and commercial-content disclosure. ViralShort does not preselect privacy or automatically publish TikTok posts. Disconnecting deletes active TikTok tokens; access can also be revoked in TikTok account settings.

Meta and Instagram API

When a user connects Facebook, ViralShort requests Page and Instagram publishing permissions only for Pages the user manages. If that Page has a linked Instagram professional account, the user may publish Reels to it. We store Page tokens, selected Page and Instagram account identifiers, and the Meta user identifier required to honor Meta data-deletion callbacks.

Users can disconnect a destination at any time to remove active tokens. Meta-initiated deletion requests are processed through our signed callback and receive a status URL and confirmation code on the data deletion page.

Third-Party Services

We use third-party services for infrastructure and publishing operations, such as authentication, storage, compute, and distribution — including Google, YouTube API Services, Facebook, and TikTok for publishing to user-owned channels. These services only receive the information needed to perform their role.

Data Security

We use managed infrastructure, HTTPS transport, scoped credentials, and operational controls to protect account data and generated assets.

Data Retention & Deletion

Active OAuth tokens are deleted immediately when a destination is disconnected or a valid provider deletion request is received. Provider deletion receipts retain only a one-way hash, status, and confirmation code for up to 90 days. Following complete account termination, customer account data and generated outputs are retained for up to 30 days for export and recovery, then deleted unless a longer period is legally required.

Your Rights

  • Access your personal data
  • Request correction of inaccurate information
  • Request deletion where applicable
  • Request export of your data in a portable format

Changes to This Policy

We may update this privacy policy from time to time. We will post the updated version here and revise the effective date.

Contact Us

If you have any questions about this privacy policy or our data practices, contact us at support@viralshort.net or visit our support page.