Privacy Policy
Last updated: June 5, 2026
This Privacy Policy explains how YFaceViral ("we", "us", the "Service"), operated by [YOUR LEGAL NAME], collects, uses, stores, and shares information about you when you use our website at yfaceviral.com and the related application (collectively, the "Service"). By using the Service you agree to the practices described here.
1. Information we collect
1.1 Information you give us
- Account data — your email address, display name, profile picture URL, and password (managed by our auth provider, Clerk).
- Content data — the topics, scripts, voice selections, niche preferences, and any other inputs you provide to generate videos.
- Billing data — when you subscribe or buy credit packs, our payments processor (Stripe) collects your card details directly. We never see or store your full card number; we receive a tokenized customer identifier and the last four digits.
- Support correspondence — anything you send to support@yfaceviral.com.
1.2 Information from YouTube and Google
When you connect a YouTube channel, the Service uses YouTube API Services to access information about your channel on your behalf. After you grant consent on Google's OAuth screen, we receive:
- Your YouTube channel ID, channel title, thumbnail URL, and the access + refresh tokens issued by Google.
- The metadata of videos we upload on your behalf (video ID, title, description, tags, privacy status).
We use this data only to upload the videos you explicitly approve to the channel you selected. We do not read your comments, your subscribers, your watch history, or any video you did not create through the Service.
Use of the Service is also subject to the YouTube Terms of Service and the Google Privacy Policy. By connecting your YouTube channel you agree to both.
1.3 Information we collect automatically
- Usage data — pages visited, features used, generation counts, timestamps. Stored in our application database.
- Device + log data — IP address, browser user-agent, request timing. Used for security, abuse prevention, and debugging. Logs are retained for 30 days unless an investigation requires longer.
- Error data — when something fails, we capture the stack trace and the request context to Sentry. We deliberately scrub authorization headers, cookies, and payment signatures before transmission.
2. How we use your information
- To research, draft, narrate, edit, and upload videos that you request.
- To authenticate your sessions and protect your account.
- To bill you, process refunds, and prevent fraud.
- To send transactional emails (receipts, subscription notices, security alerts).
- To debug, improve, and operate the Service. We do not use your generated content to train any AI model.
- To comply with legal obligations.
3. Third-party processors we share data with
We share the minimum data required for each processor to perform its function. Each processor has its own privacy policy linked below.
- Clerk — authentication and user identity. Privacy
- Stripe — payment processing. Privacy
- Google / YouTube — YouTube API Services for channel access and video uploads. Privacy
- Anthropic — Claude API for script generation. We send your topic + niche; we do not send Google account data. Privacy
- Tavily — web research for video topics. Privacy
- Cloudflare R2 / AWS S3 — storage for rendered video files.
- Railway — infrastructure hosting. Privacy
- Sentry — error monitoring (PII scrubbed by default). Privacy
4. How we store and protect your information
OAuth refresh tokens are encrypted at rest using Fernet symmetric encryption before they touch the database. Data in transit uses TLS 1.2 or higher. Access to production systems is limited to the operator and protected by strong authentication.
No system is perfectly secure. If we discover a breach affecting your data we will notify you within 72 hours of confirmation, as required by applicable law.
5. How long we keep your information
- Account + content data — for as long as your account is active. Deleted when you close the account.
- Rendered videos — until you delete them or delete your account.
- Billing records — 7 years, as required by tax law.
- Logs — 30 days.
- YouTube/Google API data — refresh tokens are deleted within 30 days of you disconnecting the channel or closing your account. We also honour revocation through the Google Permissions page (see Section 7).
6. Your rights
Depending on where you live, you may have the right to access, correct, export, restrict processing of, or delete your personal data. To exercise any of these rights, email support@yfaceviral.com from the address on your account. We respond within 30 days.
You also have the right to lodge a complaint with your local data protection authority (in the UK, the Information Commissioner's Office).
7. Revoking YouTube / Google access
You can revoke the Service's access to your Google account at any time at https://myaccount.google.com/permissions. Revoking access stops all further uploads and invalidates the stored refresh token; the next backend job that tries to use it will fail cleanly.
8. Children
The Service is not directed to anyone under 18. We do not knowingly collect personal data from children. If we discover that we have, we will delete it.
9. International transfers
We process data in the United Kingdom, the United States, and the European Union depending on which processor is involved. Where required, transfers rely on the appropriate safeguards (Standard Contractual Clauses or equivalent).
10. Changes to this policy
If we make material changes, we will email you and post the updated policy here with a new "Last updated" date at least 14 days before the changes take effect.
11. Contact
Operator: [YOUR LEGAL NAME]
Email: support@yfaceviral.com
Website: yfaceviral.com
