Privacy Policy
In short: ViralForge only accesses the social media accounts you choose to connect. It uses that access to publish content you have reviewed and approved, and to show how that content performs. We never sell your data, never use it for advertising, and delete stored account access as soon as you disconnect.
1. Who we are
ViralForge (the "Service") is a content planning and publishing tool available at https://viral-forge.hs-apps.cloud. It is operated by Stephen Maina ("we", "us"). You can contact us about privacy at stephenmaina02@gmail.com.
This policy explains what information the Service collects, including information received through the Facebook, Instagram, YouTube and TikTok APIs, how it is used and shared, and the choices you have.
2. Information we collect
Account information
For people with a ViralForge login we store a name, an email address and a securely hashed password.
Information from social accounts you connect
We only receive this information when you connect an account and grant permission on the platform's own consent screen.
| Platform | What we store |
|---|---|
| Your Facebook user ID and name, the IDs and names of Facebook Pages you manage, and access tokens for your account and the Page you choose to publish to. | |
| The ID and username of the Instagram professional account linked to your Facebook Page, and the access token used to publish to it. | |
| YouTube | Your Google account ID, your YouTube channel name, and OAuth access and refresh tokens. |
| TikTok | Your TikTok open ID, display name and username, and OAuth access and refresh tokens. |
Performance data
For content published through the Service and for connected accounts, we collect aggregate statistics such as views, impressions, reach, likes or reactions, the number of comments, shares and saves, watch time, and follower or subscriber counts. We do not collect the text of comments, private messages, or the identities of people who follow or interact with your accounts.
Content you create
Topics, scripts, captions, hashtags, images and videos created in the Service, along with reviewer notes, approval decisions and publishing schedules.
Technical information
IP addresses and timestamps recorded in activity and server logs, and cookies required to keep you signed in. We do not use advertising or tracking cookies.
3. How we use information
- To publish content to the accounts you connected, and only after an authorised reviewer has approved that content.
- To schedule posts, show publishing status, and display performance and monetisation eligibility progress for your accounts.
- To keep connections working, for example by refreshing access tokens before they expire.
- To secure the Service, prevent abuse, and keep an audit trail of approvals and changes.
We do not sell personal information, use it for advertising, build profiles of individuals, or use data received from Facebook, Instagram, YouTube or TikTok to train artificial intelligence models.
4. How information is shared
We share information only with the service providers needed to run the Service:
- Meta, Google (YouTube) and TikTok, to publish your approved content and read its performance, under their own privacy policies.
- AI providers (Anthropic and OpenAI), which receive topic descriptions, channel descriptions, brand voice guidelines and image prompts in order to draft content. They do not receive your social account data or access tokens.
- ElevenLabs, which receives script text to create voiceovers.
- Pexels and Pixabay, which receive short search phrases to find stock footage.
- Our hosting provider, which stores the Service's servers and backups.
We may also disclose information if required by law, or to protect the rights and safety of users and the public.
5. YouTube API Services and Google user data
The Service uses YouTube API Services. By connecting a YouTube account you agree to be bound by the YouTube Terms of Service, and Google's handling of your data is described in the Google Privacy Policy.
ViralForge's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. You can revoke ViralForge's access to your Google account at any time at myaccount.google.com/permissions.
6. Security
Access tokens are encrypted at rest, passwords are hashed, and the Service is only available over encrypted HTTPS connections. Access to connected accounts is limited to the authorised users of each channel. No method of storage or transmission is completely secure, but we work to protect your information.
7. How long we keep information
- Access tokens and connected account details are kept while the account is connected, and deleted immediately when you disconnect it, delete the channel, delete your ViralForge account, or remove the app from the platform.
- Content, publishing records and performance data are kept while the related channel exists, and deleted on request.
- Generated media for rejected or failed content is deleted automatically after 30 days.
- Server logs and backups are kept for up to 14 days.
8. Your choices and rights
- Disconnect an account at any time from the channel's connections screen in ViralForge.
- Remove access from the platform: Facebook and Instagram under Settings, Business integrations or Apps and websites; Google at myaccount.google.com/permissions; TikTok under Settings and privacy, Security, Manage app permissions.
- Request deletion by following the steps on our data deletion page.
- Access, correct or delete other information we hold about you by emailing stephenmaina02@gmail.com. We respond within 30 days.
Depending on where you live, you may also have the right to object to processing, to data portability, and to complain to your local data protection authority.
9. Children
The Service is not intended for anyone under 18, and we do not knowingly collect information from children.
10. International processing
Our service providers may process information in countries other than yours, including the United States. We rely on their contractual and legal safeguards for these transfers.
11. Changes to this policy
We will update the effective date above when this policy changes, and highlight significant changes in the Service.
12. Contact
Questions or requests: stephenmaina02@gmail.com.