Privacy Policy
What we collect
Your email address (to associate your scans with you) and the channel identifier you submit. A free channel analysis uses publicly available YouTube data only, we do not access your account or private analytics unless you explicitly connect your own channel with Google (see YouTube data below).
Accounts
If you create an account (email + password or Google sign-in), we store your login email, your connected channel identifiers (YouTube channel, and any TikTok or Instagram handles you add), and your scan history so your dashboard works. Authentication is handled by Supabase; Google sign-in shares only your name, email, and profile photo with us. Passwords are hashed, we never see them.
YouTube data and the YouTube API Services
ViralSidekick uses the YouTube API Services. Connecting your channel is optional; if you choose to, you sign in with Google and grant read-only access. By connecting, you agree to the YouTube Terms of Service, and your use of Google data is subject to the Google Privacy Policy.
What we access (read-only, and only after you connect): your YouTube channel details and statistics, your list of videos, and your YouTube Analytics reports such as views, watch time, audience retention, impressions, click-through rate, traffic sources, and demographics. We request read-only scopes only. We never post, edit, or delete anything on your channel.
How we use it: solely to generate your coaching, grade, trends, and analytics inside your own dashboard. We do not sell it, we do not use it for advertising, and we do not share it with anyone except the AI provider that produces your analysis, which receives only the metrics needed and never your login or token. ViralSidekick's use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
Storage and revoking: we store your channel identity, the analytics that power your dashboard, and a Google authorization token so we can refresh your numbers, the token is kept server-side and never exposed to your browser or any third party. You can revoke ViralSidekick's access at any time in your Google Account at myaccount.google.com/permissions, or email us to delete your stored Google data and token. Revoking stops all future access immediately.
TikTok data and the TikTok API
Connecting your TikTok account is optional. If you choose to connect it, you sign in with TikTok (Login Kit) and grant read-only access, and by doing so you agree to the TikTok Terms of Service. ViralSidekick's use of information received from the TikTok API follows the TikTok Developer Terms and platform policies.
What we access (read-only): using the TikTok Display API, we access your basic TikTok profile (display name and avatar) and your list of videos with their public metrics such as view count, like count, comment count, and share count. We request the user.info.basic and video.list scopes only. We never post, edit, delete, or message on your behalf, and we never see your password.
What we do with it: your TikTok data is used only to generate your grade, coaching, and per-post analytics inside your own dashboard. We do not sell it, we do not use it for advertising, and we share it only with the AI provider that produces your analysis, which receives the video metrics needed for coaching and never receives your login or access token.
Storage and revoking: we store your TikTok account identifier and an authorization token so we can refresh your numbers, and that token is kept server-side and never exposed to your browser or any third party. You can disconnect TikTok inside ViralSidekick at any time, revoke access in the TikTok app under Settings and privacy → Security and permissions → Apps, or email us to delete your stored TikTok data and token. Revoking stops all future access immediately.
What we do with it
We generate your report, store the scan so you can get it again, and may email you about your report or the product. No spam. We never sell your data.
AI processing
Public channel statistics (titles, view counts, publish dates) are sent to AI providers (OpenAI) to generate your analysis. No personal account data is included.
Payments
Handled entirely by Stripe. We never see or store card numbers.
Deletion
Email contact@stromation.com and we delete your data. Simple as that.