Legal

Privacy Policy

Last updated: June 19, 2026

This policy explains what ViralCut collects when you use the product, who we share it with, and the controls you have. It reflects how the product actually works today — no marketing fluff.

1. What we collect

Account information. When you sign up we store your email, name, and a scrypt-hashed password. If you use Google sign-in we receive your Google profile email and name only — never your Google password.

Connected social accounts. When you connect a TikTok account we store the OAuth access and refresh tokens TikTok issues, along with your TikTok display name, username, avatar URL, and follower count. We use these tokens solely to publish clips you explicitly schedule.

Your content. Source videos you upload or fetch from YouTube, the transcripts we generate, the clips we render, and any exports — these are stored in your project so you can revisit, re-render, or publish them.

Usage data. Standard server logs (IP address, user agent, timestamps) for security and rate limiting. We do not run third-party analytics or advertising trackers on the app.

2. How we use it

To run the product: process your videos into clips, render exports, schedule and post to TikTok, and bill you for credits used.

To keep you signed in: short-lived JWT access tokens (15 minutes) and a 7-day rotating refresh token stored hashed in our database.

To stay reliable: server logs and error reporting so we can diagnose problems. We do not use your content to train models.

3. Third-party processors

To deliver ViralCut we send specific pieces of your data to the following processors:

  • Cloudflare R2 — stores your source videos, rendered clips, thumbnails, and export files.
  • Neon (Postgres) — stores your account, projects, transcripts, and metadata.
  • Deepgram — receives the audio track of your source video for transcription. Deepgram does not retain audio after transcription completes.
  • Google Gemini — receives your transcript to identify viral moments. Transcripts are processed in-flight; we do not enable Google's training data programs.
  • TikTok — receives rendered MP4 files and captions you choose to publish, and returns engagement metadata you can view.
  • Google — only if you choose Google sign-in.
  • Stripe — handles paid plan upgrades and top-ups. Card details go directly to Stripe; we never see or store them.

4. Retention and deletion

Source videos are automatically deleted from R2 after a short window (currently a few hours) once processing finishes. Clips, thumbnails, and exports remain until you delete the project — at which point both the database rows and the R2 objects are removed.

You can delete your entire account from Settings → Account. Deletion cascades through your projects, clips, exports, social accounts, and OAuth tokens.

5. Your rights

You can access and edit your account details, disconnect any social account, and delete projects or your full account at any time.

If you're in the EU, UK, or California: the same rights GDPR / CCPA give you apply here — access, correction, deletion, and a complaint to your local supervisory authority. Contact us to make a request.

6. Cookies

We use a single first-party cookie/local-storage entry to keep you signed in (the refresh token). We do not set advertising or cross-site tracking cookies.

7. Changes to this policy

If we make a material change we'll email account holders and update the “Last updated” date above. Continued use of ViralCut after a change means you accept the revised policy.

8. Contact

Questions about this policy or a data request? Get in touch →