Legal
Privacy Policy
Last updated: April 20, 2026
ViralRemix ("we", "our", "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform at viralremix.xyz. Please read it carefully. By using ViralRemix, you agree to the practices described here.
1. Information We Collect
Account Information
When you register, we collect your email address, name, and authentication credentials. If you sign in via Google OAuth, we receive your public profile information as permitted by your Google account settings.
Usage Data
We collect information about how you interact with ViralRemix, including pages visited, features used, remix history, and session duration. This helps us improve the platform and your experience.
Workspace & Content Data
We store the brand voice definitions, content remixes, and workspace configurations you create. This data is strictly isolated per workspace and never shared across accounts.
Payment Information
Billing is processed through Stripe. We never store your full credit card number. We only retain the last four digits, card type, and expiry date for display purposes.
Technical Data
We automatically collect IP addresses, browser type, operating system, and referral URLs for security, analytics, and fraud prevention purposes.
2. How We Use Your Information
Service Delivery
We use your data to operate ViralRemix, process remixes, maintain your brand voice profiles, and deliver the features you've subscribed to.
Communication
We send transactional emails (receipts, password resets, usage alerts) and, with your consent, product updates and feature announcements. You may unsubscribe from marketing emails at any time.
Analytics & Improvement
Aggregated, anonymized usage data helps us understand which features are most valuable and where to invest in improvements. We use PostHog for product analytics.
Security
We monitor for fraud, abuse, and unauthorized access. Suspicious activity may result in account suspension and law enforcement notification where legally required.
3. Data Sharing & Disclosure
We Do Not Sell Your Data
ViralRemix does not sell, rent, or trade your personal information to third parties for marketing purposes. Period.
Service Providers
We share data with trusted sub-processors who help us operate the platform: Convex (database and authentication), Stripe (payments), Resend (transactional email), PostHog (product analytics), OpenRouter (AI model routing for remix generation), Apify (public social-media scraping), and Upstash (queue management and rate limiting). Each is bound by a data processing agreement and processes data only on our instructions.
Legal Requirements
We may disclose your information if required by law, court order, or to protect the rights, property, or safety of ViralRemix, our users, or the public.
Business Transfers
In the event of a merger, acquisition, or sale of assets, user data may be transferred. We will notify you via email and a prominent notice on our website before your data becomes subject to a different privacy policy.
4. Data Security
Encryption
All data is encrypted in transit using TLS 1.3 and at rest using AES-256. Database connections use row-level security to ensure workspace data isolation.
Access Controls
Employee access to production data is strictly limited on a need-to-know basis and requires multi-factor authentication. Access logs are reviewed regularly.
Incident Response
In the event of a data breach affecting your personal information, we will notify you within 72 hours of discovery as required by applicable data protection laws.
5. Your Rights
Access & Portability
You may request a copy of all personal data we hold about you in a machine-readable format at any time from your account settings.
Correction
You may update inaccurate personal information directly in your account settings or by contacting us.
Deletion
You may request deletion of your account and all associated data. We will process deletion requests within 30 days. Note that some data may be retained for up to 90 days in backups before permanent deletion.
GDPR & CCPA
If you are located in the European Economic Area or California, you have additional rights under GDPR and CCPA respectively, including the right to object to processing and the right to opt out of the sale of personal information (we do not sell data). Contact us at privacy@viralremix.xyz to exercise these rights.
7. Data Retention
Active Accounts
We retain your data for as long as your account is active or as needed to provide services.
Cancelled Accounts
Upon account cancellation, your workspace data is retained for 30 days to allow for reactivation. After 30 days, data is permanently deleted from our systems within 90 days.
8. Contact Us
Privacy Inquiries
For privacy-related questions, data subject requests, or to report a concern, contact our privacy team at privacy@viralremix.xyz. We respond to all inquiries within 5 business days.
Questions about this policy? privacy@viralremix.xyz