Privacy Policy

Updated September 25, 2026

Last updated: September 25, 2026

This policy explains how [Company legal name] ("we") handles personal data when you use ViralForge AI.

Data we collect

  • Account data from Google sign-in: name, email address and profile picture.
  • YouTube data when you connect a channel: channel ID, title, handle, thumbnail, subscriber, view and video counts, and analytics for videos you publish through us. We store OAuth refresh tokens encrypted (AES-256-GCM).
  • Content: your prompts, generated scripts, audio, images, videos, thumbnails and metadata.
  • Billing data: handled by Stripe. We receive your plan, invoice history, card brand, last four digits and a card fingerprint. We never see or store full card numbers.
  • Security and anti-abuse signals: a normalized form of your email, hashed IP address, a device identifier derived from browser characteristics, a first-party device cookie, and the card fingerprint above. These enforce our one-account-per-person rule and prevent trial abuse.
  • Usage data: pages viewed, features used, error logs.

How we use it

To provide and secure the Service, generate and publish your videos, show you analytics, process payments, prevent fraud and duplicate accounts, provide support, and improve the product. Our legal bases (where GDPR applies) are contract performance, legitimate interests (security, fraud prevention, product improvement) and consent where required.

Google API data

Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We use YouTube data only to provide features you request. We do not sell it, use it for advertising, or let humans read it except with your permission, for security, or to comply with law. See also the Google Privacy Policy.

You can revoke access at any time at Google security settings. When you disconnect a channel we revoke the token and delete it. Stored YouTube statistics are deleted or refreshed within 30 days, as the YouTube API Services policies require.

Processors we share data with

  • Google (sign-in, YouTube API)
  • Stripe (payments)
  • AI providers that process prompts and generate media, such as Anthropic, ElevenLabs, OpenAI and fal.ai
  • Pexels (stock footage search; only search keywords are sent)
  • Our hosting provider and email delivery provider

Each processor only receives what it needs to perform its service.

Retention

Rendered video files are kept for 30 days after creation (configurable) and then deleted from our servers; they remain on YouTube if you published them. Account data is kept while your account is active. When you delete your account, personal data is deleted within 30 days, except records we must keep for tax, fraud prevention or legal reasons.

Your rights

You can access, export, correct or delete your data from Settings, or by contacting us. Depending on where you live you may also object to or restrict processing and complain to your data protection authority.

Cookies

See our Cookie Policy.

Children

The Service is not intended for anyone under 18.

Contact

[email protected], [registered address].