Legal
Privacy Policy
Effective date: May 8, 2026 · Last reviewed: May 8, 2026
This policy explains how Virality Labs ("we", "our", or "us") collects, uses, and protects information about you when you use our platform at virality-labs.com. Please read it carefully.
1. Overview
Virality Labs is a YouTube content optimization platform. We analyze video content — via direct upload or YouTube URL — to predict viral potential, generate AI-powered suggestions, and help creators grow their channels.
We are the data controller for personal data provided directly to us (account information, uploaded content). For data processed on your behalf (e.g., your subscribers' data if you share channel statistics), you remain the data controller and we act as a data processor.
We are committed to transparent, minimal data collection and will never sell your personal information to third parties.
2. Data We Collect
2.1 Account & Identity Data
When you register or sign in:
- Email address (required for account creation)
- Password (hashed — we never store it in plaintext)
- Profile metadata: subscription plan, credit balance, account created date
- Optional: YouTube channel handle you voluntarily connect
2.2 Content You Submit
- Uploaded video files — temporarily stored during processing (typically minutes). Permanently deleted from our servers once analysis is complete or within 24 hours, whichever is sooner.
- YouTube URLs — used to fetch publicly available video metadata and captions via the YouTube Data API v3. We do not store the raw video file for YouTube-sourced analyses.
- Thumbnail images — for uploaded videos, a thumbnail may be stored on Cloudflare R2 to display in your report. For YouTube videos, we link directly to YouTube's CDN and do not copy the image.
- Video title — used for display purposes and as context for AI analysis.
2.3 Analysis Results
We store the output of each analysis (viral score, AI-generated titles, hashtags, feedback text, transcript excerpt up to 1,000 characters) linked to your account. This lets you revisit past reports. You can delete individual reports at any time.
2.4 Payment & Billing Data
Payments are processed by Polar (polar.sh). We store only your subscription plan, credit balance, and subscription status. Full card details, billing address, and payment method data are held exclusively by Polar under their own privacy policy. We never have access to your raw card data.
2.5 Usage & Technical Data
Automatically collected when you use the platform:
- IP address (used for security, fraud prevention, and approximate geolocation)
- Browser type, operating system, device type
- Pages visited, time spent, features used (via Google Analytics 4)
- Referring URL
- Timestamps of actions (video submissions, logins)
2.6 YouTube Channel Data (Optional)
If you voluntarily connect your YouTube channel handle, we retrieve — via the public YouTube Data API v3 — your channel's subscriber count, total view count, recent video metadata (titles, publish dates, view/like/comment counts), and category information. We cache this data for up to 24 hours to reduce API quota usage. This data is tied to your account and deleted when you disconnect your channel or close your account.
We do not use OAuth and therefore have no access to your YouTube Analytics, private video data, subscriber identities, or any non-public YouTube information.
3. How We Use Your Data
| Purpose | Data Used |
|---|---|
| Provide the analysis service | Video file / URL, transcript, thumbnail |
| Account authentication & security | Email, password hash, IP address |
| Display and store your reports | Analysis results, video title, thumbnail URL |
| Process payments & manage credits | Subscription plan, credit balance (via Polar) |
| Improve our AI models & scoring algorithms | Aggregated, anonymised analysis data only |
| Send transactional emails (receipt, password reset) | Email address |
| Detect fraud & abuse | IP address, usage patterns |
| Understand usage patterns & improve the product | Usage data via Google Analytics 4 |
| Respond to support requests | Email, account information |
| Comply with legal obligations | As required by applicable law |
We do not use your content or analysis results to train third-party AI models without explicit consent. Aggregated, anonymised statistics (e.g., "average viral score in the Gaming category") may be used internally.
4. Legal Basis for Processing (GDPR / UK GDPR)
If you are located in the European Economic Area (EEA), United Kingdom, or a jurisdiction with equivalent data protection laws, we rely on the following legal bases:
- ▸Contract (Art. 6(1)(b) GDPR): Processing necessary to provide the service you signed up for — account creation, video analysis, report generation, credit management.
- ▸Legitimate Interests (Art. 6(1)(f) GDPR): Security monitoring, fraud prevention, product analytics, and improving the service — where these interests are not overridden by your rights.
- ▸Legal Obligation (Art. 6(1)(c) GDPR): Retaining certain financial records to comply with tax and accounting regulations.
- ▸Consent (Art. 6(1)(a) GDPR): Non-essential cookies and marketing communications — where we have obtained your explicit consent. You may withdraw consent at any time.
6. Data Retention
- ▸Uploaded video files: Deleted immediately after analysis completes, or within 24 hours — whichever is sooner.
- ▸Audio files (extracted for transcription): Deleted as soon as transcription is returned, typically within minutes.
- ▸Analysis reports & results: Retained while your account is active. You can delete individual reports at any time from your dashboard.
- ▸Account data (email, profile): Retained while your account is active, and for up to 30 days after deletion to allow recovery. Permanently purged thereafter.
- ▸Payment records: 7 years to comply with accounting and tax regulations (processed by Polar; we retain only plan/status metadata).
- ▸Thumbnail images (uploaded videos): Retained while the corresponding report exists. Deleted when you delete the report or your account.
- ▸YouTube channel stats cache: Up to 24 hours from last sync. Deleted immediately when you disconnect your channel or close your account.
- ▸Analytics data: Retained for up to 14 months by our analytics provider. Data is anonymised at the point of collection.
- ▸Server logs (IP, access logs): Up to 90 days for security purposes, then purged.
7. International Data Transfers
Virality Labs is operated from and data is primarily processed in the United States. If you access the service from the EEA, UK, or other regions with data transfer restrictions, your data will be transferred internationally.
We rely on the following safeguards for international transfers:
- Standard Contractual Clauses (SCCs) — for transfers to processors established in the US, where the processor has executed SCCs with us or their customers.
- Data Privacy Framework (DPF) — where applicable sub-processors (e.g., Google, Cloudflare) are certified under the EU-U.S. Data Privacy Framework.
- Adequacy decisions — where the European Commission has determined the recipient country provides adequate protection.
You may request a copy of the relevant transfer mechanism by contacting us at hello@virality-labs.com.
8. Your Rights
Depending on your location, you may have the following rights regarding your personal data. To exercise any of these rights, contact us at hello@virality-labs.com. We will respond within 30 days (extendable by a further 60 days for complex requests, with notice).
Right of Access
Obtain a copy of the personal data we hold about you.
Right to Rectification
Correct inaccurate or incomplete personal data.
Right to Erasure ("Right to be Forgotten")
Request deletion of your personal data. We will comply unless a legal obligation requires retention.
Right to Restriction
Ask us to pause processing your data in certain circumstances.
Right to Data Portability
Receive your data in a structured, machine-readable format (JSON/CSV) to transfer to another service.
Right to Object
Object to processing based on legitimate interests, including profiling.
Right to Withdraw Consent
Withdraw consent at any time where processing is consent-based. This does not affect prior processing.
Right to Lodge a Complaint
File a complaint with your local data protection authority (e.g., ICO in the UK, relevant EU DPA).
Most account data (email, reports) can be managed directly from your Account Settings. Account deletion is available in Settings → Delete Account.
9. California Residents — CCPA / CPRA
If you are a California resident, the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) grant you the following additional rights:
- Right to Know — request disclosure of the categories and specific pieces of personal information we have collected about you, the sources, the business purpose, and the categories of third parties with whom we share it.
- Right to Delete — request deletion of personal information we have collected, subject to certain exceptions.
- Right to Correct — request correction of inaccurate personal information.
- Right to Opt-Out of Sale or Sharing — we do not sell or share personal information for cross-context behavioral advertising. No opt-out is required.
- Right to Limit Use of Sensitive Personal Information — we do not collect or process sensitive personal information as defined under CPRA (e.g., social security numbers, precise geolocation, biometric data).
- Non-Discrimination — we will not discriminate against you for exercising your CCPA rights.
To submit a verifiable consumer request, email hello@virality-labs.com with subject line "CCPA Request". We will verify your identity before processing. You may also designate an authorised agent to submit requests on your behalf.
Categories of personal information collected in the past 12 months: Identifiers (email, IP), commercial information (subscription, credits), internet/electronic activity (usage logs, pages visited), inferences drawn from usage data. No sensitive personal information as defined by CPRA.
11. Children's Privacy
Virality Labs is not directed to individuals under the age of 16 (or 13 in jurisdictions that permit it with parental consent). We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us at hello@virality-labs.com and we will delete it promptly.
12. Security
We implement industry-standard technical and organisational measures to protect your personal data, including:
- TLS/HTTPS encryption for all data in transit
- AES-256 encryption for data at rest
- Passwords stored as hashed and salted digests — never in plaintext
- Strict access controls — principle of least privilege across all internal systems
- Uploaded video and audio files isolated in ephemeral directories and purged immediately after processing
- No raw payment card data ever touches our servers — handled exclusively by our PCI-compliant payment processor
- Regular dependency audits and security reviews
Despite these measures, no internet transmission is 100% secure. If you discover a security vulnerability, please disclose it responsibly to hello@virality-labs.com.
In the event of a data breach affecting your rights and freedoms, we will notify the relevant supervisory authority within 72 hours (GDPR Art. 33) and notify affected users without undue delay (GDPR Art. 34).
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make material changes, we will:
- Update the "Effective date" at the top of this page
- Send an email notification to registered users
- Display an in-app banner for 14 days after the change takes effect
Your continued use of the service after the effective date constitutes acceptance of the updated policy. If you do not agree, you may close your account before the effective date.
14. Contact & Data Protection Officer
For any privacy-related questions, requests, or complaints, please contact us:
If you are an EU/UK resident and are not satisfied with our response, you have the right to lodge a complaint with your local data protection supervisory authority:
- EU: Your national DPA (list at edpb.europa.eu)
- UK: Information Commissioner's Office (ICO) at ico.org.uk
© 2026 Virality Labs. This privacy policy was last reviewed on May 8, 2026.