Introduction
ViralShort (“we”, “our”, or “us”) is a workflow system for generating and publishing automated video content. We are committed to protecting the privacy of operators, collaborators, and end users whose data may pass through the platform.
Information We Collect
We collect the information necessary to provide and operate the service:
- Account information: Email address, display name, and authentication metadata.
- Workflow data: Prompts, generated assets, subtitles, metadata, publish records, and job execution history.
- Device and session information: Browser, platform, and technical data required for compatibility and security.
- Billing information: Subscription or payment data handled by our payment providers. We do not store full card numbers.
How We Use Your Information
- To provide and improve workflow automation and publishing features
- To save prompts, outputs, and settings associated with your projects
- To process payments and subscriptions where applicable
- To provide support and investigate failures or abuse
- To send service-related notifications and product updates
Generated Content
ViralShort stores prompts, generated media, subtitles, and publishing metadata to support production, retries, moderation, and history auditing. We do not sell generated content or account data to advertisers.
YouTube API Services
ViralShort uses YouTube API Servicesto publish videos to YouTube channels that our users own and operate. When a user connects a YouTube channel, we request OAuth authorization and store the resulting access and refresh tokens solely to upload videos and manage their metadata (titles, descriptions, tags, thumbnails, and privacy status) on that user’s own channels. We do not use YouTube API Services to collect or analyze data from channels our users do not control.
By using ViralShort you also agree to the YouTube Terms of Service. Data we obtain through YouTube API Services is handled in accordance with the Google Privacy Policy.
You can revoke ViralShort’s access to your YouTube account at any time. Disconnect the channel from within ViralShort, or remove ViralShort’s access through the Google security settings page at https://security.google.com/settings/security/permissions. When access is revoked, we stop using the associated tokens and delete them from active systems.
TikTok Login Kit and Content Posting API
ViralShort uses TikTok Login Kit so a workspace administrator can connect a TikTok account they control. We request user.info.basic to identify the authorized account and video.publish for creator-approved direct posting. ViralShort never accesses unrelated TikTok accounts or videos.
Every TikTok video enters a review queue. Before any publish API call, the user sees the 9:16 video, editable caption, destination account, current privacy options, interaction controls, AI-content notice, and commercial-content disclosure. ViralShort does not preselect privacy or automatically publish TikTok posts. Disconnecting deletes active TikTok tokens; access can also be revoked in TikTok account settings.
Meta and Instagram API
When a user connects Facebook, ViralShort requests Page and Instagram publishing permissions only for Pages the user manages. If that Page has a linked Instagram professional account, the user may publish Reels to it. We store Page tokens, selected Page and Instagram account identifiers, and the Meta user identifier required to honor Meta data-deletion callbacks.
Users can disconnect a destination at any time to remove active tokens. Meta-initiated deletion requests are processed through our signed callback and receive a status URL and confirmation code on the data deletion page.
Third-Party Services
We use third-party services for infrastructure and publishing operations, such as authentication, storage, compute, and distribution — including Google, YouTube API Services, Facebook, and TikTok for publishing to user-owned channels. These services only receive the information needed to perform their role.
Data Security
We use managed infrastructure, HTTPS transport, scoped credentials, and operational controls to protect account data and generated assets.
Data Retention & Deletion
Active OAuth tokens are deleted immediately when a destination is disconnected or a valid provider deletion request is received. Provider deletion receipts retain only a one-way hash, status, and confirmation code for up to 90 days. Following complete account termination, customer account data and generated outputs are retained for up to 30 days for export and recovery, then deleted unless a longer period is legally required.
Your Rights
- Access your personal data
- Request correction of inaccurate information
- Request deletion where applicable
- Request export of your data in a portable format
Changes to This Policy
We may update this privacy policy from time to time. We will post the updated version here and revise the effective date.
Contact Us
If you have any questions about this privacy policy or our data practices, contact us at support@viralshort.net or visit our support page.