ViralShark

Privacy Policy

Last updated 1 September 2026

1. Who we are

ViralShark operates the service at viralshark.app and is the controller of the personal data described here. This policy explains what we collect, why, who else processes it, and how to have it removed.

2. What we collect

  • Account data: your name, email address and profile image, passed to us by your sign in provider through Clerk. We never receive or store your password.
  • What you tell the assistant: your messages, the niche and accounts you enter during onboarding, and any corrections you make.
  • Usage data: which pages you open, which features you use, and errors the app hits.
  • Technical data: IP address, browser and device type, collected automatically by our hosting provider as part of serving the site.
  • Billing data: your subscription status and billing history. Card details go directly to Stripe and never reach our servers.

3. Signing in with Google or Apple

When you sign in with Google we receive only your name, email address and profile picture, and only because you approved that on the Google consent screen. We use it to create your account, to identify you when you return, and to email you about your subscription.

We do not read your Gmail, Drive, Calendar, Contacts or any other Google service, and we do not request access to them. We do not sell data obtained through Google sign in, and we do not use it for advertising. Apple sign in works the same way, and if you use Apple private relay we only ever see the relay address.

You can disconnect ViralShark from your Google account at any time in your Google account settings. Doing so stops you being able to sign in; to have the stored data deleted as well, email us.

4. Why we use it

  • To run the service and answer what you ask the assistant.
  • To take payment and manage your subscription.
  • To keep the shared library from being consumed unfairly by one account.
  • To fix bugs and understand which parts of the product get used.
  • To email you about your account, billing, or a material change to the service.

Where the law requires a legal basis, ours is performance of a contract for the first two, and legitimate interest for the rest.

5. Content collected from TikTok and Instagram

The library holds publicly available posts: video URLs, captions, hashtags, sounds, view and engagement counts, and the public handle that posted them. This is collected from public pages only. We do not access private accounts, and we do not attempt to identify anyone beyond the public handle they chose.

The library is shared across all accounts rather than copied per customer. Nothing you type is added to it. If a post of yours is in the library and you want it out, email us with the link and we will remove it.

6. Analytics and cookies

We use cookies that are necessary to keep you signed in, set by Clerk. Beyond that we use Vercel Analytics, which counts page views without cookies and without profiling individuals, and PostHog for product analytics, which records which features you use so we can see what is worth building. PostHog events are tied to your account id.

We do not run advertising trackers and we do not sell data to anyone.

7. Who processes your data

We use the following providers. Each processes data only to deliver their part of the service.

  • Clerk: authentication and account records.
  • Convex: the database and backend that stores your chats, settings and subscription state.
  • Vercel: hosting, page delivery and page view analytics.
  • Stripe: payments, subscriptions and card data.
  • PostHog: product analytics.
  • Anthropic and Google: the AI models that generate responses. Your messages are sent to them to produce an answer.
  • Apify: collecting public posts from TikTok and Instagram. It receives search terms and handles, not your personal data.
  • OpenAI and Voyage AI: turning library text into embeddings for search.

We will also disclose data where the law requires it, or to protect our rights or the safety of others.

8. AI providers and training

Messages you send are passed to the AI providers listed above so they can produce a response. We do not use your conversations to train our own models, and we use these providers under terms that exclude your data from training theirs.

9. How long we keep it

Account data and chats are kept while your account is open. Delete a chat and its messages go with it immediately. Close your account and we delete your personal data within 30 days, except records we are required to keep for tax and accounting, which Stripe holds for as long as the law requires.

Public posts in the shared library are not personal data of yours and stay in the library after you leave.

10. Your rights

Depending on where you live you can ask us to give you a copy of your data, correct it, delete it, restrict how we use it, or object to that use. Email us and we will respond within 30 days. You will not be charged and you will not be treated differently for asking.

If you are in the EEA or the UK and are unhappy with our response you can complain to your local data protection authority.

11. Security

Data is encrypted in transit and at rest by our providers. Access to production data is limited to those who need it. No system is perfectly secure, and if a breach affects you we will tell you without undue delay.

12. Children

The service is not for anyone under 18. We do not knowingly collect data from children. If you believe a child has an account, email us and we will delete it.

13. International transfers

Our providers operate in the United States and elsewhere, so your data may be processed outside your country. Where that involves personal data leaving the EEA or the UK, our providers rely on standard contractual clauses.

14. Changes

We can update this policy. The date at the top always reflects the current version, and we will tell you by email or in the product before a material change takes effect.

15. Contact

Privacy questions, data requests and takedown requests go to support@viralshark.app.