Back to Home

Privacy Policy

Last updated: 8/22/2026

1. Introduction

This Privacy Policy describes how Infinee s. r. o. ("we", "our", or "us") collects, uses, and protects your personal information when you use ViralSky, our AI-powered viral content generation platform.

Data Controller: Infinee s. r. o., a Slovak limited liability company, is the data controller responsible for your personal information.

By using our service, you agree to the collection and use of information in accordance with this policy. We are committed to protecting your privacy and complying with applicable data protection laws, including the General Data Protection Regulation (GDPR).

2. Information We Collect

We collect information that you provide directly to us, including:

  • Account Information: Email address, name, and password (hashed and encrypted)
  • Content Data: Topics, prompts, and content you generate using our service
  • Payment Information: Processed securely through Stripe (we do not store credit card details)
  • Subscription Data: Subscription tier, billing period, and payment history
  • Social Media Account Information: When you connect a Facebook Page, LinkedIn profile, X account, or Threads account to ViralSky's scheduler, we receive and store: the platform display name and profile picture, the platform-assigned account or page ID, and a reference identifier to the OAuth integration held by our scheduling sub-processor (Postiz). We do not store the OAuth access tokens themselves — those are held only by Postiz and used to publish the scheduled content you authorise. See Section 6 for the full list of permissions we request per platform and why.
  • Scheduled Posts: The text, media references, target platforms, and publish times for posts you schedule, plus their delivery status (pending, sent, published, failed) and the resulting platform post URL once published.
  • Usage Data: Analytics, feature usage, and interaction patterns
  • Technical Data: IP address, browser type, device information, and access logs

We may also collect information automatically through cookies and similar tracking technologies as described in Section 7.

3. How We Use Your Information

We use the information we collect for the following purposes:

  • Service Delivery: Provide, maintain, and improve our AI content generation services
  • Account Management: Create and manage your account, process subscriptions, and handle billing
  • Payment Processing: Process transactions securely through Stripe
  • Social Media Posting: When you connect a social account and schedule a post, we use the information you provided (and the OAuth authorisation held by Postiz) solely to publish the content you authored at the time you chose, to the destinations you selected. We do not use your social account data for any other purpose, including profiling, advertising targeting, or training AI models.
  • Communication: Send technical notices, support messages, and respond to inquiries
  • Service Improvement: Analyze usage patterns to improve our AI models and service features (data anonymized where possible). Content you publish via the scheduler is never used to train AI models.
  • Legal Compliance: Comply with legal obligations and protect our rights
  • Security: Detect and prevent fraud, abuse, and security issues

Legal Basis for Processing (GDPR): We process your personal data based on: (1) your consent when you create an account, (2) contract performance to provide our services, (3) legitimate interests for service improvement and security, and (4) legal obligations for compliance purposes.

4. Data Security

We implement appropriate technical and organizational measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction, including:

  • Encryption of data in transit (HTTPS/TLS) and at rest
  • Secure password hashing and authentication
  • Regular security assessments and updates
  • Access controls and limited data access on a need-to-know basis
  • Secure payment processing through Stripe (we never store credit card details)

However, no method of transmission over the Internet or electronic storage is 100% secure. While we strive to protect your personal information, we cannot guarantee absolute security.

5. Third-Party Services

We use third-party services that may collect or process information on our behalf:

  • Stripe: Payment processing and subscription management. Stripe handles all payment information securely. See Stripe's Privacy Policy
  • NextAuth: Authentication services for secure login
  • AI Providers: Content generation services including OpenAI, Anthropic (Claude), Google AI (Gemini), and XAI. Your prompts and generated content may be processed by these providers. See their respective privacy policies:
  • Postiz (scheduling sub-processor): We use a self-hosted instance of Postiz (open-source social media scheduler) to perform the OAuth authorisation flows with each social platform and to publish your scheduled content at the time you specify. Postiz holds the OAuth access tokens issued by each platform; ViralSky only stores a reference identifier and your account's display name and avatar. Postiz runs on infrastructure controlled by Infinee s. r. o. inside the European Union (Hetzner, Falkenstein, Germany). See Postiz's Privacy Policy.
  • Meta Platforms (Facebook, Instagram, Threads): When you connect a Facebook Page, Instagram Business account, or Threads account, Meta processes the OAuth authorisation. We request only the permissions necessary to publish posts on your behalf and to display your account in our UI (see Section 6 for the full list of scopes). See Meta's Privacy Policy and the Meta Platform Terms.
  • LinkedIn: When you connect a LinkedIn account, LinkedIn processes the OAuth authorisation. We request only the permissions necessary to publish posts on your behalf (see Section 6). See LinkedIn's Privacy Policy.
  • X (formerly Twitter): Where supported, X processes the OAuth authorisation. See X's Privacy Policy.
  • PostHog: Analytics and product analytics (anonymized where possible)
  • Resend: Email delivery services

These third-party services have their own privacy policies. We encourage you to review them. We are not responsible for the privacy practices of these third parties.

6. Social Media Account Connections (Meta, LinkedIn, X, Threads)

ViralSky's scheduler lets you connect one or more social media accounts and publish AI-generated content to them on a schedule. This section sets out exactly what data we receive from each platform, what we do with it, and how you can revoke our access at any time.

6.1 How the connection works

When you click Connect on a platform, you are redirected to that platform's own OAuth authorisation screen. The platform asks you to grant a specific set of permissions to our application. We never see your platform login credentials. Once you approve, the platform issues an OAuth access token. That token is received and stored only by Postiz, our self-hosted scheduling sub-processor (see Section 5). ViralSky itself only stores a reference identifier to the integration record in Postiz, plus your account's display name and avatar (so we can show you which account you connected).

6.2 Permissions we request and why

We request only the permissions strictly necessary to publish the posts you schedule and to display your account in our UI. We do not request, store, or read any of your messages, friends/followers lists, private content, or analytics beyond what is shown to you in the scheduler.

Facebook Pages

  • pages_show_list — to display the list of Facebook Pages you administer so you can pick which one to publish to.
  • pages_manage_posts — to publish the post you scheduled to the Page you selected.
  • pages_read_engagement — to confirm a publish succeeded and to display the resulting post URL back to you.
  • business_management — required by Facebook Login for Business so you can grant ViralSky access to a Page that is owned by your Business Portfolio.

We do not request pages_read_user_content, pages_manage_engagement, or read_insights. ViralSky does not read visitor comments or ratings, does not moderate Page comments, and does not display Facebook Insights in the product.

LinkedIn (personal profile)

  • openid, profile — to confirm your identity and display your name/avatar in our UI.
  • w_member_social — to publish posts and (optionally) first-comment continuations on your behalf.

Threads, X (Twitter), Instagram

Threads, X, and Instagram support are planned for future releases. When enabled, the equivalent "publish posts on your behalf" permissions will be requested and disclosed here.

6.3 Use, sharing, and retention of social account data

  • We use platform data solely to deliver the scheduler feature: publishing content you authored, at the time you scheduled, to the destinations you selected.
  • We do not sell or rent platform data, do not use it for advertising or profiling, and do not use the content of your scheduled posts to train AI models.
  • We do share data with Postiz (our scheduling sub-processor — see Section 5) and the destination social platform itself (which is the entire point of publishing a post).
  • OAuth access tokens are stored and managed by Postiz inside the European Union, with industry-standard encryption. We rotate or revoke them automatically when the connected platform indicates that the token is no longer valid.
  • Connection metadata (display name, avatar, integration reference) is retained while the account is connected, and for up to 90 days after disconnection for support and audit purposes. After that, it is permanently deleted.

6.4 How to disconnect a social account or delete your data

You can revoke ViralSky's access to a connected social account at any time, in any of the following ways:

  • In ViralSky: Open /scheduler, find the account in the "Connected accounts" card, and click Disconnect. The OAuth token will be invalidated by our system and our reference record will be deactivated immediately.
  • From the platform side: You can also remove ViralSky from the connected applications list inside the platform itself — e.g. Facebook Settings → Business Integrations, LinkedIn → Permitted Services, etc. The platform will inform us via the OAuth refresh mechanism and we will deactivate the corresponding record.
  • Full data deletion: Follow the instructions on our Data Deletion page, or email info@viralsky.ai. We will erase all connection metadata, scheduled posts, and audit logs associated with that platform account within 30 days of the request.

6.5 Platform-specific terms

Your connection to each social platform is also subject to that platform's own terms. In particular, by connecting a Facebook, Instagram, or Threads account you acknowledge the Meta Platform Terms and the Meta Privacy Policy; by connecting a LinkedIn account you acknowledge the LinkedIn API Terms of Use.

7. Your Rights (GDPR)

Under the General Data Protection Regulation (GDPR) and applicable data protection laws, you have the following rights:

  • Right of Access: Request a copy of your personal data we hold
  • Right to Rectification: Correct inaccurate or incomplete personal data
  • Right to Erasure: Request deletion of your personal data ("right to be forgotten")
  • Right to Restrict Processing: Request limitation of how we process your data
  • Right to Data Portability: Receive your data in a structured, machine-readable format
  • Right to Object: Object to processing based on legitimate interests
  • Right to Withdraw Consent: Withdraw consent at any time where processing is based on consent
  • Right to Disconnect Social Accounts: Revoke ViralSky's access to any connected social media account (Facebook, LinkedIn, etc.) at any time — see Section 6.4 for the available methods
  • Right to Lodge a Complaint: File a complaint with your local data protection authority

To exercise these rights, please contact us at info@viralsky.ai or follow the instructions on our Data Deletion page. We will respond to your request within 30 days.

Account Deletion: You may delete your account at any time through your account settings. Upon deletion, we will remove your personal data, except where we are required to retain it for legal or legitimate business purposes (e.g., transaction records for tax purposes).

8. Cookies and Tracking Technologies

We use cookies and similar tracking technologies to track activity on our service and hold certain information. Types of cookies we use:

  • Essential Cookies: Required for authentication and core functionality
  • Analytics Cookies: Help us understand how users interact with our service (anonymized)
  • Preference Cookies: Remember your settings and preferences

You can instruct your browser to refuse all cookies or to indicate when a cookie is being sent. However, if you do not accept cookies, you may not be able to use some portions of our service.

9. Data Retention

We retain your personal information for as long as necessary to provide our services and fulfill the purposes described in this policy:

  • Account Data: Retained while your account is active and for up to 3 years after account deletion for legal and business purposes
  • Content Data: Retained while your account is active. You may delete generated content at any time
  • Social Account Connections: Display name, avatar and integration reference are retained while the account is connected, and for up to 90 days after disconnection. OAuth access tokens are held by Postiz and are invalidated immediately on disconnect. Scheduled-post records (including platform URLs of published posts) are retained for 12 months for audit purposes, then anonymised.
  • Payment Records: Retained for 7 years as required by Slovak tax and accounting laws
  • Analytics Data: Retained in anonymized form for service improvement

After the retention period, we will securely delete or anonymize your personal data, except where legal obligations require us to retain it.

10. International Data Transfers

Your information may be transferred to and processed in countries outside the European Economic Area (EEA), including the United States, where our third-party service providers operate. These transfers are necessary for providing our services.

We ensure appropriate safeguards are in place for such transfers, including Standard Contractual Clauses approved by the European Commission, to protect your personal data in accordance with GDPR requirements.

11. Children's Privacy

Our service is not intended for users under the age of 18. We do not knowingly collect personal information from children under 18. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately. If we become aware that we have collected personal information from a child under 18, we will take steps to delete such information.

12. Changes to This Policy

We may update our Privacy Policy from time to time. We will notify you of any material changes by:

  • Posting the new Privacy Policy on this page
  • Updating the "Last updated" date
  • Sending an email notification for significant changes (if you have an account)

Your continued use of our service after any changes constitutes acceptance of the updated Privacy Policy.

13. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or your personal data, please contact us:

Infinee s. r. o.

Babuškova 3107/3

821 03 Bratislava - Ružinov

Slovakia

Company ID (IČO): 55986773

Tax ID (DIČ): 2122153110

Email: info@viralsky.ai

Data Protection Authority: If you are located in the EU and have concerns about our data processing, you may contact the Slovak Data Protection Authority: Úrad na ochranu osobných údajov Slovenskej republiky