LEGAL

Privacy Policy

This policy explains what personal information ListenViral handles, why we use it, who may receive it, and the choices available to you.

Last updated: August 26, 2026

1. Scope and who we are

This Privacy Policy applies to the ListenViral website, web application, tracking agents, reports, alerts, and related support services (together, the “Service”). ListenViral is the controller of personal information collected directly through the Service unless a separate notice says otherwise.

This policy does not govern the privacy practices of TikTok, YouTube, or other websites and services that you visit through a link in ListenViral. Their own notices apply to their services.

2. Information we collect

We may collect the following categories of information:

  • Account information: your name, email address, password hash, profile image, Google account identifier when you use Google sign-in, plan, and account status.
  • Tracking instructions and creator content:niches, keywords, hashtags, exclusions, filters, public creator handles, labels, alert settings, saved ideas, notes, and other instructions you submit.
  • Delivery information: an email address you choose for reports, delivery status, and a masked copy of the destination in stored reports.
  • Public platform information: public posts, captions, profile handles, engagement metrics, thumbnails, publication times, and related public signals from supported social platforms.
  • Usage and device information: IP address, user agent, browser or device information, login and session times, feature interactions, request records, error details, and security or audit events.
  • Communications: messages, attachments, and contact details you provide when you ask for support, submit a privacy request, or otherwise contact us.
  • Billing information: if paid plans are offered, our payment provider may process your payment method and billing details. We may receive customer and subscription identifiers, plan status, transaction status, and limited billing details. We do not need to store your complete card number.

3. Where information comes from

We receive information:

  • directly from you when you create and use an account;
  • automatically from your browser, device, and interactions with the Service;
  • from Google when you choose Google sign-in, according to the permissions shown during that flow;
  • from supported platforms and data providers that make public content and metrics available; and
  • from people who contact us on your behalf.

4. How and why we use information

We use personal information only when we have a valid reason. The reason depends on the information and your relationship with us.

PurposeInformation involvedReason
Provide the ServiceAccount, tracking, public platform, saved, and delivery informationPerform our contract with you and take steps you request
Personalize and improve resultsTracking instructions, filters, usage, and feedbackPerform our contract and pursue our legitimate interest in improving the Service
Secure and operate ListenViralSession, IP address, user agent, logs, errors, and audit eventsLegitimate interests in security, reliability, abuse prevention, and enforcing our terms
Send reports and service messagesEmail address, alert settings, and account eventsPerform our contract, respond to your request, or obtain consent where required
Manage plans and paymentsAccount, plan, transaction status, and billing identifiersPerform our contract and meet accounting or legal obligations
Respond and complyCommunications, account records, and relevant service activityRespond to you, comply with law, and establish or defend legal claims

Where we rely on consent, you may withdraw it at any time. Withdrawal does not affect processing that already occurred. Where we rely on legitimate interests, we consider the impact on your rights and use safeguards appropriate to the activity.

5. How we disclose information

We do not sell personal information. We also do not share personal information for cross-context behavioral advertising. We may disclose information in these circumstances:

  • Infrastructure and storage providers that host the website, application, databases, caching, and background jobs. Depending on the deployment, these may include Vercel, Render, MongoDB, and a Redis hosting provider.
  • Identity and payment providers such as Google for optional sign-in and Stripe if paid billing is enabled.
  • Platform and public-data providers used to find and refresh public content. These may include YouTube services, Apify, TikHub, and EnsembleData. Search terms, public handles, and similar tracking instructions may be sent to these providers.
  • AI service providers used to suggest search terms, analyze public content, or generate a creative breakdown. Depending on availability, these may include Anthropic, Google Gemini, and Groq. We may send tracking prompts and relevant public content to the provider selected for a request. We do not send your password.
  • Communication providers such as Brevo or an SMTP relay when you request email delivery.
  • Security and diagnostics providers such as Sentry or an observability service when those tools are enabled.
  • Authorities and affected parties when reasonably necessary to comply with law, protect rights and safety, investigate abuse, or respond to valid legal process.
  • A successor business as part of a merger, financing, acquisition, reorganization, or sale of assets, subject to appropriate confidentiality and notice requirements.

Providers may process information only for the services they supply to us or as otherwise disclosed in their own terms when you interact with them directly.

6. International transfers

ListenViral and its providers may process information in countries other than the one where you live. Those countries may have different privacy laws. When required, we use an approved transfer mechanism and appropriate safeguards, such as contractual data protection clauses, and assess additional protections for the transfer.

7. How long we keep information

We keep information only as long as reasonably needed for the purposes described above, including security, dispute resolution, and legal obligations. Current default operational periods include:

InformationTypical retention
Account, agents, and saved ideasWhile the account is active, then for the time needed to complete deletion, resolve disputes, prevent fraud, and meet legal obligations
Active login session recordsUp to 30 days by default, or earlier when the session expires or is revoked
Password reset recordsAbout 30 minutes by default, after which automated expiry applies
Raw provider responsesUp to 72 hours by default
Normalized viral resultsUp to 90 days by default, unless saved or copied into a report
Scheduled report snapshotsUp to 180 days by default
Administrative audit eventsUp to 365 days by default
Support and legal communicationsAs long as needed to answer the request and maintain an appropriate record

These periods may be shorter or longer when required by law, needed for a legal claim, or necessary to protect the Service. Deletion from backups may take additional time until the relevant backup cycle completes.

8. How we protect information

We use administrative, technical, and operational safeguards designed for the nature of the information we handle. These include encrypted transport, access controls, tenant separation, password hashing, short-lived reset links, hashed session-token records, session rotation, rate limits, security logging, and restricted access to production systems.

No method of storage or transmission is completely secure. You can help by using a unique password, protecting your sign-in method, and contacting us promptly if you believe your account has been compromised.

9. Your privacy rights

Depending on where you live, you may have the right to request access to personal information, correction, deletion, portability, restriction, or objection to certain processing. You may also have the right to withdraw consent, appeal a request decision, and lodge a complaint with your local privacy or data protection authority.

To make a request, email passivecraftcontact@gmail.com with the subject “ListenViral privacy request.” Describe the right you want to exercise and identify the account involved. We may ask for information needed to verify your identity and authority. Authorized agents may submit a request where local law permits, subject to verification.

We will not discriminate against you for exercising a privacy right. Some information may be exempt from a request, or may need to be retained for security, legal, or contractual reasons. If so, we will explain the applicable reason when the law allows.

10. Cookies and local storage

ListenViral uses cookies that are necessary to sign you in, refresh your session, protect requests from forgery, and keep the Service secure. These cookies may be marked HttpOnly, Secure, and SameSite where appropriate. Refusing necessary cookies may prevent account features from working.

We use browser local storage to remember preferences such as the selected visual theme. We do not currently use advertising cookies or third-party behavioral advertising tools. If that changes, we will update this policy and provide consent controls where required.

11. Children

ListenViral is not directed to children under 16, and we do not knowingly collect personal information from them. If you believe a child has provided personal information, contact us so we can review and delete it where appropriate.

12. Changes to this policy

We may update this policy as the Service, our providers, or legal requirements change. We will post the revised policy here and update the date at the top. If a change materially affects how we use personal information, we will provide additional notice when required.

13. Contact us

Questions, requests, and complaints about this policy can be sent to ListenViral at passivecraftcontact@gmail.com. You can also use our contact page to choose the right subject line.