Privacy policy
Last updated: August 25, 2026
This privacy policy describes how ViralHookAnalyzer (we, us, our) collects, uses, stores, shares, and protects information when you use the website, creator tools, account features, and optional Google/YouTube connection.
What we collect
- Account information: your email address, name, profile image, authentication provider, account identifier, and subscription status when you create or use an account.
- Inputs and content: video URLs, prompts, text, uploaded media, saved analyses, projects, favorites, and other information you intentionally submit to VHA.
- Usage data: Anonymous analytics about pages visited, features used, and approximate location at country or region level.
- Cookies: Strictly necessary cookies, plus analytics and advertising cookies where consent applies.
Google and YouTube user data
Connecting YouTube is optional. When you choose to connect it, VHA requests read-only Google OAuth permissions for basic identity information and YouTube channel data. Depending on the permissions you approve and features you use, we may access your Google account name, email address and profile image; YouTube channel ID, title, image and public channel totals; recent uploaded-video IDs, titles, thumbnails, publication dates and public engagement totals; and read-only YouTube Analytics data needed for channel-intelligence features. VHA does not request permission to create, edit, upload, or delete your YouTube videos.
We use Google user data only to authenticate you, display the connected channel, synchronize your recent videos and channel metrics, reuse your existing VHA analyses, and provide the channel-intelligence features you request. We do not use Google user data for advertising, retargeting, credit decisions, sale to data brokers, or training generalized AI or machine-learning models.
ViralHookAnalyzer's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
How we use it
- To run the analysis or tool action you requested.
- To maintain your account, saved work, subscription, and optional YouTube connection.
- To improve VHA functionality, reliability, and output quality using service telemetry and feedback that does not include Google OAuth tokens.
- To prevent abuse, enforce fair usage limits, and keep the service stable.
- To serve and measure advertising where consent applies, without using Google API user data for that purpose.
How we protect sensitive data
- Encryption in transit: VHA and its production APIs use HTTPS/TLS to protect data sent between your browser, VHA, Google, and our service providers.
- OAuth token encryption: Google access and refresh tokens are additionally encrypted before database storage using authenticated AES-256-GCM encryption with a server-held key and a unique random initialization vector.
- Server-side secrets: OAuth client secrets, token-encryption keys, refresh tokens, and API credentials are never embedded in or returned to the browser.
- Access controls: database row-level security limits connection records to the owning authenticated user, while privileged service access is restricted to server-side operations required to provide the service.
- Least privilege: VHA requests read-only YouTube scopes and uses time-limited access tokens. Signed, time-limited OAuth state protects the connection callback.
- Operational safeguards: we use input validation, abuse controls, logging, dependency review, and restricted administrative access. We investigate suspected incidents and take steps to contain, remediate, and notify affected users when legally required.
Third-party services
We use service providers for hosting, managed authentication and database services, payment processing, AI inference, analytics, error monitoring, email delivery, and advertising. They may process only the information needed to perform services for VHA under their contractual and security obligations. We do not sell Google user data or disclose it to third parties except when necessary to provide a user-requested feature, comply with law, protect users and the service, or complete a business transfer subject to applicable notice and safeguards.
Google AdSense
We use Google AdSense to display advertisements. Google may use cookies and device identifiers to serve ads based on your prior visits to this and other websites. You can opt out of personalized advertising at adssettings.google.com.
Data retention
Account information and saved VHA content are retained while your account is active and for as long as reasonably necessary to provide the service, meet legal obligations, resolve disputes, and prevent abuse. Google OAuth access and refresh tokens are retained only while your YouTube connection remains active. Choosing Disconnect YouTube causes VHA to request revocation at Google and removes the stored access token, refresh token, and token expiry. Choosing the connection deletion option removes the complete stored YouTube connection record. Residual encrypted backups, where applicable, expire under our provider's backup cycle.
Public video metadata and VHA analyses you intentionally create or share may remain until you delete them or request deletion. We do not use your submissions or Google user data to train external or generalized AI models.
Your choices and deletion rights
You can disconnect YouTube from the YouTube dashboard and can separately revoke VHA access from your Google Account permissions. You may request access to, correction of, export of, or deletion of personal data we hold about you, including deletion of your account and stored Google/YouTube connection data. Contact us through the contact page. We may need to verify your identity before completing a request.
Children
The service is not directed at children under 13. We do not knowingly collect data from them.
Changes
We may update this policy as the platform evolves. Material changes will be highlighted on this page.
