Last updated: June 19, 2026
This policy explains what ViralCut collects when you use the product, who we share it with, and the controls you have. It reflects how the product actually works today — no marketing fluff.
Account information. When you sign up we store your email, name, and a scrypt-hashed password. If you use Google sign-in we receive your Google profile email and name only — never your Google password.
Connected social accounts. When you connect a TikTok account we store the OAuth access and refresh tokens TikTok issues, along with your TikTok display name, username, avatar URL, and follower count. We use these tokens solely to publish clips you explicitly schedule.
Your content. Source videos you upload or fetch from YouTube, the transcripts we generate, the clips we render, and any exports — these are stored in your project so you can revisit, re-render, or publish them.
Usage data. Standard server logs (IP address, user agent, timestamps) for security and rate limiting. We do not run third-party analytics or advertising trackers on the app.
To run the product: process your videos into clips, render exports, schedule and post to TikTok, and bill you for credits used.
To keep you signed in: short-lived JWT access tokens (15 minutes) and a 7-day rotating refresh token stored hashed in our database.
To stay reliable: server logs and error reporting so we can diagnose problems. We do not use your content to train models.
To deliver ViralCut we send specific pieces of your data to the following processors:
Source videos are automatically deleted from R2 after a short window (currently a few hours) once processing finishes. Clips, thumbnails, and exports remain until you delete the project — at which point both the database rows and the R2 objects are removed.
You can delete your entire account from Settings → Account. Deletion cascades through your projects, clips, exports, social accounts, and OAuth tokens.
You can access and edit your account details, disconnect any social account, and delete projects or your full account at any time.
If you're in the EU, UK, or California: the same rights GDPR / CCPA give you apply here — access, correction, deletion, and a complaint to your local supervisory authority. Contact us to make a request.
We use a single first-party cookie/local-storage entry to keep you signed in (the refresh token). We do not set advertising or cross-site tracking cookies.
If we make a material change we'll email account holders and update the “Last updated” date above. Continued use of ViralCut after a change means you accept the revised policy.
Questions about this policy or a data request? Get in touch →