ViralWhenViralWhen
Sign in

Privacy Policy

Effective August 20, 2026

This policy explains what personal data ViralWhen collects, why, who else sees it, where it is stored, and how you can get it back or have it deleted. ViralWhen is operated by Collector Vault (“we”, “us”). It applies to the ViralWhen web application, its APIs, and this website.

We are based in Singapore and handle personal data under the Personal Data Protection Act 2012 (PDPA). If you are in the EU, EEA or UK, section 10 sets out the additional rights you have under the GDPR and how we meet them.

1. Data we collect

Account data. Your email address and name, your password (stored only as a hash by our authentication provider), the organisations you belong to, your role in them, and invitations you send or accept.

Content you provide. Everything you upload or write in the product: footage, images, product photos, logos, audio, screen recordings, brand details, and the briefs, prompts and chat messages you send to the AI agents.

Likeness data. Some of what you upload is a person’s face — a portrait used to create a presenter, or footage in which people appear. We treat this as sensitive and describe it separately in section 6.

Generated output. The scripts, keyframes, voiceovers, avatar takes, videos and variants the pipeline produces from your inputs, plus the intermediate records of each stage (what each agent decided and why), which is how a run can be inspected, resumed or refunded.

Billing data. Your plan, credit balance and transaction history. Card details are entered directly with our payment processor and never reach our servers; we store only the identifiers and invoice records it returns.

Connected social accounts. If you connect a channel (TikTok, Instagram, YouTube, X or Pinterest) we store the handle, display name and the access and refresh tokens needed to publish on your behalf and to read back the performance of what you published.

Usage and technical data. Product analytics events, error diagnostics, IP address, browser and device information, and server logs. These are used to operate, secure and debug the Service.

2. Why we use it, and on what basis

To provide the Service — generating, rendering, storing and delivering your videos, and running your account, organisation and billing. Under the PDPA this is data you provide voluntarily for a purpose you would reasonably expect; under the GDPR it is performance of our contract with you.

To keep it working and secure — diagnostics, abuse prevention, rate limiting, and fixing defects. This is our legitimate interest in operating a reliable service.

To improve output quality — we measure how generations perform (which hooks, layouts and formats do better) and feed those signals back into the pipeline. This uses the outcome of your generations within your own organisation, and aggregate patterns across the platform that do not identify you or your business.

To communicate with you — service notices, beta invitations, and replies to your requests.

We do not sell personal data, and we do not use your content to advertise to you.

3. Automated processing you should know about

The Service is a chain of automated agents. Your brief, your uploaded assets and your brand details are processed by large language models, image models, a text-to-speech model and a video model in order to produce a video. Quality gates in that chain automatically score, and can automatically reject, a generation.

None of this produces a decision with a legal or similarly significant effect on you — it produces a video, which you review before doing anything with it. You can stop a run at any time, and you can ask a human (us) to look at any outcome you disagree with.

4. Service providers who process data for us

We do not run our own datacentre. Running ViralWhen means these providers process data on our behalf, each under its own terms and security commitments:

Supabase — database and authentication (account data, all application records). Backblaze B2 — object storage for your uploads and rendered videos. Vercel — application hosting, request logs and web analytics. Modal — the GPU and CPU compute that renders avatars and composites video. Stripe — payments and invoicing. PostHog — product analytics. Sentry — error tracking. cron-job.org — scheduled triggers for background jobs.

5. AI providers, and what we do not promise about training

Producing a video sends parts of your content to third-party model providers:

OpenRouter routes text to the language models that write and review your brief, script and direction — so your brief, brand details and script reach the model provider behind it. Fish Audio receives your script text to synthesise the voiceover. fal.ai receives images — including reference portraits — for keyframe generation and background removal, when those providers are enabled. Our own GPU containers on Modal run the avatar animation and the final composite.

What we can tell you honestly: we do not grant any provider the right to use your content for their own purposes, and we send only what a stage needs. But each provider operates under its own terms, and we do not currently hold a signed no-training commitment from every one of them. We will not claim otherwise on this page. If that matters to your business — and for a brand’s footage and a person’s face it reasonably might — write to us at privacy@viralwhen.com before uploading, and we will tell you exactly which providers are enabled on your account and what their terms say.

6. Faces, voices and likeness

A portrait you upload is used to generate a presenter and to animate that presenter speaking your script. That image, and frames derived from it, are stored with your organisation’s assets and are sent to the image and video providers named above as part of generating your video.

We do not use faces for identification, verification or biometric matching, we do not build a face database across customers, and we do not use one customer’s likeness in another customer’s video.

You must have the right to upload the face. If it is not your own, you need that person’s permission, and depending on where they live, that permission may need to be explicit and in writing. This is a condition of using the Service (see the Terms), and it is the obligation customers most often overlook.

7. Where your data is stored, and international transfers

Your uploads and rendered videos are stored in the United States (our object storage region is US East), our database and application are hosted with providers whose infrastructure is also primarily in the United States, and the AI providers in section 5 process data in the United States and other countries.

Where we transfer personal data out of Singapore, we take steps intended to ensure the recipient is bound to a standard of protection comparable to the PDPA, through the contractual terms those providers offer. For transfers of EU, EEA or UK data we rely on the transfer mechanisms in those providers’ data-processing terms, including the European Commission’s Standard Contractual Clauses where they apply.

8. Cookies and similar technologies

Strictly necessary — session cookies that keep you signed in, set by our authentication provider, and a cookie recording which organisation you are currently working in. The Service cannot function without these.

Analytics — product analytics and web analytics that tell us which features are used and where the product fails. We do not use advertising cookies and we do not run third-party ad trackers on this site.

9. How long we keep it

Account and content data — for as long as your account exists. Deleting your account removes your account record and the organisations you solely own, together with their projects, generations and stored assets.

Billing records — retained after deletion where we are required to keep them for tax and accounting purposes.

Logs and diagnostics — retained on a short rolling window by our hosting and error-tracking providers, then discarded automatically.

Backups — deleted data can persist in encrypted database backups for a limited period before those backups age out.

10. Your rights, and how to use them

In the product, without asking us: you can export your data as a file from Settings, and you can delete your account and the organisations you solely own from the same screen. Deletion is permanent — export first if you want a copy.

Under the PDPA you may ask for access to the personal data we hold about you and information about how it has been used, ask us to correct it, and withdraw consent for uses that rely on consent (withdrawing consent may mean we can no longer provide the Service). We will respond to an access request as soon as reasonably possible, and normally within 30 days; if we need longer we will tell you when to expect a response.

Under the GDPR, if you are in the EU, EEA or UK, you also have the rights to erasure, restriction of processing, data portability, and to object to processing based on legitimate interests. Where you have given consent you may withdraw it at any time without affecting processing already carried out.

To exercise any of these, email privacy@viralwhen.com. We may need to verify that the request comes from you. If you are unhappy with our response you can complain to the Personal Data Protection Commission of Singapore (PDPC), or to your local supervisory authority if you are in the EU, EEA or UK.

11. Security, and what we cannot promise

Data is encrypted in transit. Access to your organisation’s data is scoped to its members and enforced on every request; stored files are served through short-lived signed links rather than public URLs. Administrative access is limited to what is needed to operate and support the Service.

No system is perfectly secure, and we will not tell you otherwise. If a data breach occurs that is likely to result in significant harm to you, or that meets the notification thresholds under the PDPA, we will notify the affected users and the regulator as required by law.

12. Children

The Service is not intended for anyone under 18 and accounts are restricted to adults. We do not knowingly collect personal data from children. If you believe a child has provided us data, contact us and we will delete it.

13. Changes to this policy

We may update this policy as the product changes — particularly as AI providers are added or replaced, which is the part of this document most likely to move. Material changes will be reflected in the effective date above and, where the change affects how your content is processed, notified in the product before it takes effect.

Questions? Contact us at privacy@viralwhen.com.