Back

Legal

Privacy Policy

Last updated: April 18, 2026

1. Introduction

Virloq ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AI-powered video creation and social media management platform ("the Service").

2. Information We Collect

2.1 Information You Provide

  • Account Information: name, email address, password (hashed)
  • Profile Information: brand kit details, content preferences, niche settings
  • Content: scripts, prompts, video descriptions, captions you create
  • Social Media Credentials: handles, emails, and OAuth tokens for connected platforms
  • Payment Information: processed securely through third-party payment providers

2.2 Information Collected Automatically

  • Usage Data: features used, content generated, posting activity
  • Device Information: browser type, operating system, device identifiers
  • Log Data: IP address, access times, pages viewed, referral URLs
  • Cookies: session cookies for authentication and preferences

2.3 Third-Party Data

  • Social Media Platforms: channel info, follower counts, post performance data when you connect accounts
  • AI Services: prompts and content sent to AI providers (OpenAI) for generation

3. How We Use Your Information

We use collected information to:

  • Provide, operate, and maintain the Service
  • Generate AI content (scripts, videos, images) based on your inputs
  • Post content to your connected social media accounts on your behalf
  • Improve and personalise your experience
  • Analyse usage patterns to improve the Service
  • Communicate updates, security alerts, and support messages
  • Prevent fraud, abuse, and enforce our Terms of Service
  • Comply with legal obligations

4. Data Sharing and Disclosure

We may share your information with:

  • AI Service Providers: OpenAI (for script, video, and image generation) — your prompts are sent to generate content
  • Social Media Platforms: content and credentials for posting (Twitter/X, YouTube, Instagram, TikTok, LinkedIn)
  • Cloud Infrastructure: hosting and storage providers for secure data storage
  • Legal Requirements: when required by law, regulation, or legal process

We do not sell your personal information to third parties. We do not use your content to train AI models.

4a. TikTok Data Handling

When you connect a TikTok account to Virloq via TikTok’s OAuth 2.0 Login Kit, we receive and store only the fields necessary to power the integration. This section describes exactly what we collect, why, how long we keep it, and how you can revoke or delete it.

What TikTok data we collect

  • Open ID & Union ID — TikTok’s stable identifiers for your account, used to scope your data to your Virloq user record.
  • Display name & avatar URL — shown in your Virloq Settings so you can confirm the correct TikTok account is linked (scope: user.info.basic).
  • Follower count, following count, likes count, total video count — surfaced in your Virloq dashboard so you can see your TikTok growth (scope: user.info.stats). Read-only.
  • List of your own recent TikTok video IDs, titles, thumbnails, and view counts — shown in a read-only widget so you can correlate which Virloq-generated videos performed best (scope: video.list). We do not download or republish these videos.
  • OAuth access token & refresh token — used to upload videos you create in Virloq to your TikTok inbox at your request (scope: video.upload).

What we do NOT collect from TikTok

  • Your TikTok password (we never see it — TikTok handles authentication)
  • Your direct messages, private content, or comments
  • Data about other TikTok users you interact with
  • Your browsing or watch history on TikTok

How we use TikTok data

  • Upload AI-generated videos you create in Virloq to your TikTok inbox only when you explicitly click “Post to TikTok”. We never publish without that action.
  • Display your TikTok handle, follower count, and recent post performance inside the Virloq dashboard so you can measure your own growth.

Storage and security of TikTok data

  • Stored encrypted at rest in MongoDB Atlas (US-East-1 region)
  • Scoped per Virloq user — no Virloq user can read another user’s TikTok data
  • Transmitted only over TLS 1.3 (HTTPS)
  • Access tokens are never exposed to the browser or shared with any third party
  • We do not share TikTok data with advertisers, analytics vendors, or AI training pipelines

Retention & deletion of TikTok data

  • Disconnect anytime: go to Settings → Disconnect TikTok. This immediately revokes our access tokens and deletes the associated cached TikTok profile data from our servers.
  • Full account deletion: visit our Data Deletion page to request complete removal of your Virloq account, including any TikTok tokens or cached data. Processed within 30 days; you receive a confirmation code to track the request.
  • Token expiry: TikTok access tokens naturally expire per TikTok’s OAuth policy. Expired tokens are deleted from our database within 24 hours.

Use of TikTok data within Virloq complies with TikTok’sLogin Kit Best Practices,TikTok’s Terms of Service, andTikTok’s Privacy Policy. Questions about TikTok data handling specifically? Emailprivacy@virloq.com.

5. Data Security

We implement industry-standard security measures to protect your data:

  • Passwords are hashed using bcrypt
  • Authentication via secure HTTP-only cookies with HTTPS
  • OAuth tokens for social media are stored encrypted
  • API keys are stored server-side in environment variables, never exposed to clients
  • Regular security audits and monitoring

While we strive to protect your information, no method of transmission or storage is 100% secure. We cannot guarantee absolute security.

6. Data Retention

  • Account Data: retained while your account is active
  • Generated Content: retained until you delete it or your account
  • Analytics Data: retained for up to 24 months
  • Log Data: retained for up to 90 days

You may request deletion of your data at any time by contacting us.

7. Your Rights

Depending on your jurisdiction, you may have the right to:

  • Access: request a copy of your personal data
  • Rectification: correct inaccurate personal data
  • Deletion: request deletion of your personal data
  • Portability: receive your data in a structured, machine-readable format
  • Restriction: restrict processing of your personal data
  • Objection: object to processing of your personal data
  • Withdraw Consent: where processing is based on consent

To exercise these rights, contact us at legal@virloq.com, submit a request via our Contact form, or track a pending deletion on our Data Deletion page.

8. Cookies

We use essential cookies for:

  • Authentication: keeping you logged in securely
  • Preferences: remembering your settings

We do not use tracking or advertising cookies. You can manage cookies through your browser settings.

9. Children's Privacy

The Service is not intended for users under the age of 16. We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, please contact us and we will promptly delete it.

10. International Data Transfers

Your information may be transferred to and processed in countries other than your country of residence. We ensure appropriate safeguards are in place for such transfers in compliance with applicable data protection laws.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes via email or in-app notification at least 14 days before changes take effect. Your continued use of the Service after changes constitutes acceptance.

12. Contact Us

For privacy-related questions, data requests, or to exercise your data rights:

Virloq

Email: legal@virloq.com

Website: virloq.com

Virloq © 2026. All rights reserved.Terms of Service