Privacy Policy

ViralDNA.io web platform · Last updated: August 19, 2026

ViralDNA.io ("ViralDNA", "we", "us", or "our") is a SaaS platform that provides research and creative tools for YouTube content creators. This policy explains, in detail, what information we access, collect, store and use, including YouTube API Data relating to users, what we store on or read from your device, who we share information with, how long we keep it, and how you can have it deleted.

This policy covers the web platform at viraldna.io. Our browser extension is covered by a separate Extension Privacy Policy, and the ViralDNA Auto Flow extension by its own Auto Flow Privacy Policy. Our terms are published at Terms of Service.

1. YouTube API Services

ViralDNA.io uses YouTube API Services to retrieve publicly available YouTube data. By using our application you are agreeing to be bound by the YouTube Terms of Service, which you can review here: https://www.youtube.com/t/terms

Data we obtain through the YouTube API Services is also subject to the Google Privacy Policy, which you can review here: http://www.google.com/policies/privacy

We access the YouTube Data API v3 with a server-side API key only. We do not ask you to authorize your YouTube or Google account to YouTube API Services, and we therefore never obtain OAuth access to any YouTube account. We cannot read your private or unlisted videos, your watch or search history, your subscriptions, your messages, your YouTube Analytics, or any other non-public account data, and we never take any action on your YouTube account (no uploading, commenting, liking, subscribing, or posting).

2. Information we collect and how we use it

2.1 Account information

You sign in with Google (via our authentication provider, Supabase). When you do, we receive and store: your email address, your display name, your Google profile picture URL, your Google account identifier, the internal user ID created for you, and account timestamps (created, last sign-in). We use this only to create and secure your account, to recognise you when you return, to apply your plan and credit balance, and to contact you about your account or support requests.

2.2 Subscription and usage information

If you buy a subscription or a credit pack, we store your Stripe customer ID, Stripe subscription ID, plan name, billing period end date, your credit and token balances, and a record of purchases. We never see or store your card number, CVC, or bank details; payment details are entered on Stripe's own checkout page and are processed by Stripe. We also store counters of your feature usage (for example how many analyses you have run) to enforce plan limits and to prevent abuse.

2.3 Content you submit

We store what you submit to a tool so we can produce your result and let you open it again later: video scripts and transcripts you paste or import, YouTube video and channel URLs you enter, thumbnails and reference images you upload, prompts and instructions you write, saved character descriptions, generated images, and the analysis reports and drafts we return to you. These records are tied to your account and are visible only to you.

When you use the transcript import button, we retrieve the publicly available caption text of the single video whose link you pasted, so that you do not have to type the script yourself. Nothing is imported unless you paste a link and press the button. The imported text is treated exactly like text you typed: it is used to produce your report, it is stored in that report on your account, and it is deleted when you delete the report or your account.

2.4 YouTube API Data relating to users

All YouTube data we handle is public data returned by the YouTube Data API. We do not receive any private user data from YouTube. Specifically:

WhatFieldsWhy and how long
Video metadata (from videos.list, playlistItems.list, search.list) Video ID, title, description, publication date, thumbnail URLs, duration, tags, channel ID and title, view count, like count, comment count Used to produce the analysis or discovery result you requested. Shown to you in the session, and kept inside the saved report on your account until you delete it.
Channel metadata (from channels.list, search.list) Channel ID, title, handle, avatar URL, description, subscriber count, total view count, video count, country Used for channel, competitor and niche discovery. A copy is held in our channel index (see below).
Channel index (our own search index) The channel fields listed above, plus a numeric text embedding derived from public titles and descriptions Lets us find similar channels and under-served niches without spending your quota. Every record is automatically re-fetched from the YouTube Data API, or deleted, within 30 days.
Search and result cache The query you ran and the public results returned for it Prevents repeat calls for the same query. Cleared automatically within 24 hours.

If a channel or video is deleted, terminated, or made private at YouTube, our nightly job removes the stored record. No YouTube API Data is used for advertising, profiling, credit or lending decisions, or sold to anyone.

2.5 Technical and security data

Like any web service, our servers process the technical data needed to serve a request and keep the service safe: IP address, browser user agent, request time, the endpoint called, and error diagnostics. We use it to apply rate limits, detect abuse of our API quota, debug failures, and keep accounts secure. Rate limit counters are short lived, and server logs are kept for at most 30 days.

3. Information stored on or read from your device

ViralDNA.io places and reads a small amount of information on your device using cookies and similar technologies (browser local storage and session storage). We use these only to make the product work. We do not use advertising cookies, third-party analytics, tracking pixels, device fingerprinting, or any cross-site tracking, and we do not allow third parties to place advertising or tracking technology on our site.

NameTypePurposeLifetime
sb-<project>-auth-token (and its chunked parts)Cookie, set by our authentication provider SupabaseStrictly necessary. Keeps you signed in and lets our server verify your session.Until you sign out or the session expires
viraldna_langLocal storageRemembers the interface language you chose.Until you clear it
viraldna_darkLocal storageRemembers your light or dark theme choice.Until you clear it
viraldna_promo_v1_dismissedLocal storageRemembers that you closed the announcement bar, so it stays closed.Until you clear it
vdna_saved_character, vdna_saved_charactersLocal storageKeeps the character descriptions you save in the thumbnail studio on your own device.Until you delete them
Extension connect flagSession storageUsed once during the browser extension sign-in handshake.Until the browser tab is closed

If you install our browser extension, it additionally stores your ViralDNA session token and your extension preferences on your device using chrome.storage.local; this is described in the Extension Privacy Policy. When you pay, Stripe's checkout page sets its own cookies on Stripe's domain for fraud prevention, governed by Stripe's privacy policy.

You can delete or block these at any time in your browser settings (site data, cookies and storage). Clearing them signs you out and resets your saved preferences, and blocking the authentication cookie means you cannot sign in.

4. Who we share information with

We do not sell, rent or trade your information, and we do not share it for advertising or profiling. We share only what a provider needs in order to deliver a feature you asked for:

We may also disclose information if we are legally required to do so, or to protect our rights, users and service against fraud, abuse or a security incident.

5. How long we keep information

CategoryRetention
Account and subscription recordsFor as long as your account exists, then deleted on request or after account deletion. Invoice records are kept as long as tax law requires.
Your reports, uploads and saved contentUntil you delete the item or your account.
Stored YouTube API Data (channel index)Automatically refreshed from the API, or deleted, within 30 days.
Cached YouTube search resultsCleared within 24 hours.
Server and security logsUp to 30 days.

6. Your choices and rights

Depending on where you live, you may have additional rights under the GDPR, the Turkish KVKK, or similar laws, including the right to object, to restrict processing, and to complain to your local data protection authority. We process your data to perform our contract with you (providing the service), to meet legal obligations (such as tax records), and on the basis of our legitimate interest in keeping the service secure and functional.

7. Security, transfers and children

All traffic is encrypted in transit with HTTPS. Data is stored with our providers on managed infrastructure with access restricted to the accounts that operate the service, and row level security so one user cannot read another user's records. Our providers may process data on servers in the European Union and the United States, under the safeguards published in their own privacy policies. ViralDNA.io is not directed at children under 13 (or the minimum age in your country), and we do not knowingly collect their data.

8. Changes to this policy

If we change this policy we will update the date at the top of this page and, where the change is significant, notify you in the application or by email. Continued use after an update means you accept the revised policy.

9. Contact us

For any question about this policy, to exercise a right, or to request deletion of your data, contact us at support@viraldna.io.

© 2026 ViralDNA. All rights reserved.