ViralSync

ViralSync · Legal

Privacy Policy

Last updated: October 1, 2026

1. Who we are

ViralSync (“we”, “us”) is operated by Ugur Özdamar. The full postal address is in our Imprint. You can reach us about privacy at ugur44ist@gmail.com. This policy explains what personal data ViralSync (https://viralsync.io and https://app.viralsync.io) processes, why, and what rights you have.

2. What ViralSync does

ViralSync is a workspace for brands. You upload finished videos and images once, write a post, choose the channels you own on platforms such as YouTube, TikTok, Instagram and Facebook, and publish immediately or at a scheduled time. An optional AI assistant helps prepare posts when you ask it to.

3. Data we process

  • Account data: name, email address, a password hash (never the password), sign-in method, and session and security records such as time and device information needed to keep your account safe. If you choose Google sign-in, we receive the basic profile Google shares (account ID, verified email, name, profile picture). We do not request access to Gmail, Drive or contacts.
  • Workspace data: workspace, brand and member information, roles, invitations, settings and time zones.
  • Content you provide: the media files you upload, post text, titles, descriptions, tags, schedules and per-channel settings.
  • Connected platform data: when you connect an account we receive an authorization from that platform, and the identity and public profile of the channels or pages you select (for example display name, handle, profile picture and the platform’s ID for the channel). We also record the result of each publication, such as its status and the link to the published post.
  • Usage and performance data: metering of storage and publishing actions for plan limits and, where a platform provides it, basic performance counts of posts published through ViralSync (views, likes, comments, shares).
  • AI assistant data: messages you send to the assistant and the context needed to answer, which may include your draft content and channel names.

3a. Data from TikTok, YouTube and Meta

We access a platform only after you connect your own account and approve its permission screen, and only for what the permissions allow:

  • TikTok (Login Kit and Content Posting API): user.info.basic to show which TikTok account is connected (display name, avatar and the account’s open ID) and video.publish to publish videos you choose to post, with the privacy and interaction settings you select. We use the creator information TikTok provides to show the options that are allowed for your account. We do not post anything you have not asked us to post.
  • YouTube (Google API Services): read-only access to identify your channel and permission to upload videos you choose to publish. ViralSync’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
  • Instagram and Facebook (Meta): identity of the professional account or Page you select and permission to publish content to it.

We do not sell this data, do not use it for advertising, and do not use it to train AI models. We use it only to provide the features you request.

4. Why we process it, and on what basis

To provide ViralSync and perform our contract with you (storing your media, publishing as you instruct, running your account): Art. 6(1)(b) GDPR. To keep the service secure, prevent abuse and fix errors: our legitimate interest, Art. 6(1)(f) GDPR. To comply with legal duties: Art. 6(1)(c) GDPR. Where we rely on consent, you can withdraw it at any time with effect for the future.

5. Tokens and security

Authorization tokens issued by a platform are stored encrypted and are used only to carry out actions you request for the connected account. Media is stored in private storage and is made available to a platform only through short-lived links when publishing. Access to workspace data is limited to members according to their role, and brand access is enforced separately for each brand. We do not store your passwords for social platforms; you sign in on the platform itself.

6. Who receives data

We use service providers to run ViralSync: Cloudflare (hosting, API and file storage), Neon (database), Vercel (web application hosting), Resend (transactional email), and AI model providers for the assistant when you use it. Content is sent to a social platform only when you publish to it. These providers process data on our behalf under their terms and data-processing agreements. Some of them may process data outside the EU/EEA; where this happens we rely on appropriate safeguards such as the EU Standard Contractual Clauses or an adequacy decision. We do not sell personal data.

7. Cookies and local storage

We use strictly necessary cookies for sign-in, session security and bot protection, and store your chosen appearance and sidebar state in your browser. We do not use advertising or analytics cookies.

8. Retention, disconnecting and deletion

We keep your data while your account exists. You can disconnect a connected account at any time in ViralSync (Channels → Disconnect): we then revoke the authorization at the platform where possible, delete the stored tokens and stop publishing to its channels. Posts and publication history remain in your workspace. You can also remove authorization from within the platform’s own settings. You can delete files from your library. To have your account and associated data deleted, email us at the address above; we delete or anonymize it unless we must keep it by law, and confirm when done. Backups are overwritten in the normal course of operation.

9. Your rights

Where the GDPR or similar laws apply you have the right to access, rectification, erasure, restriction, data portability and objection, and to lodge a complaint with a supervisory authority. Contact us at ugur44ist@gmail.com to exercise them.

10. Children

ViralSync is not directed at children under 16 and we do not knowingly collect their data.

11. Changes

We will update this policy when our processing changes and show the date above. Material changes will be announced in the product or by email.