← Back to ViralFarm

Privacy Policy

Effective Date: March 27, 2026 · Last Updated: October 6, 2026

This Privacy Policy is for MyViral.Farm, owned and operated by Annie Yang. ViralFarm ("ViralFarm," "we," "us," or "our") operates the website at www.myviral.farm and related services (collectively, the "Service"). This Privacy Policy describes how we collect, use, store, share, and protect information when you use the Service, including information obtained through integrations with third-party social media and commerce platforms such as Meta (Instagram, Facebook, Threads), Pinterest, LinkedIn, TikTok, X (Twitter), YouTube, and Shopify.

By using the Service, you agree to the practices described in this Privacy Policy. If you do not agree, please do not use the Service.

1. Information We Collect

1.1 Information You Provide

  • Account Information: When you register, we collect your name, email address, and profile photo via Google OAuth or email/password sign-up.
  • Content: Text, images, videos, captions, templates, and other content you create, upload, or import into the Service.
  • Payment Information: If you subscribe to a paid plan by signing up directly at myviral.farm, payment details are collected and processed by our payment processor (Stripe). If you install ViralFarm from the Shopify App Store, your charges are handled exclusively by Shopify's Billing API and appear on your Shopify invoice — we never see or store those payment details. In either case, we do not store full credit card numbers on our servers.
  • Communications: Information you provide when you contact support, submit feedback, or respond to surveys.

1.2 Information from Third-Party Platforms

When you connect a third-party account (e.g., Instagram, LinkedIn, TikTok, Pinterest, Facebook, Threads, YouTube, X, or Shopify), we may receive the following information via OAuth or platform APIs:

  • Profile / Shop Information: Username, display name, profile picture URL, account type, and account / page / shop identifiers (including Shopify shop domain such as yourstore.myshopify.com).
  • OAuth Tokens: Access tokens and refresh tokens necessary to publish content, read product listings, and perform other actions you authorize on your behalf. These tokens are encrypted at rest and stored securely.
  • Post & Publishing Data: Confirmation of post publishing status (success, failure, scheduled time), post identifiers returned by the platform, and any error messages.
  • Product / Catalog Data (Shopify): When you connect a Shopify store, we read product listings (title, description, handle, images, price, product type, tags, and inventory status) through the Shopify Admin API so you can turn them into social posts, carousels, and scheduled content. We request the minimum scopes required for these features (for example, read_products and read_product_listings). We do not request or access orders, customer PII, checkout data, discounts, fulfillment records, or payment information.

1.2.1 Temporary Caching During Publishing

Two kinds of media copies exist and are retained differently. Saved workspace media — images and videos you upload, media collections you build, and the rendered images and videos of posts you generate — is stored in our storage buckets and kept until you delete it or delete your account (see Section 5). Temporary publishing copies — files held in server memory or temporary storage only to hand a post to a destination platform — are discarded when the publish attempt finishes, whether it succeeds or fails. Where a video must be transcoded to meet a platform's format requirements or to preview in the editor, the transcoded copy is cached in our storage so it is not re-rendered on every attempt; it is treated as saved workspace media and removed with the source video or your account.

1.2.2 TikTok-Specific Data

We do not receive or store content from TikTok: no videos, comments, follower lists, or analytics are read from your TikTok account. When you publish, your post is transmitted to TikTok's API from your workspace media (Section 1.2.1). The TikTok data we retain while your account is connected is limited to your OAuth token (stored as described in Section 4), your TikTok username, display name, avatar URL, and account identifier, and the publishing status metadata TikTok returns (post/publish identifiers, success or failure, and error messages). Disconnecting the account removes the token and stops further use of these identifiers.

1.2.3 Pinterest-Specific Data

We do not read or store content from Pinterest. When you connect, we store your Pinterest username and account id, the OAuth access and refresh tokens needed to publish (Section 4), and their expiry times. Your boards are fetched from Pinterest only when you are choosing where a Pin goes and are not stored; the board id you pick is saved on that scheduled post. After publishing we keep the Pin's status and the identifiers Pinterest returns (Pin id, success or failure, error messages). Disconnecting erases the tokens.

1.2.4 Meta-Specific Data (Instagram, Facebook, Threads)

When publishing to Meta platforms, your post is transmitted to Meta's APIs from your saved workspace media. The temporary publishing copies made for that transfer are discarded when the publish attempt finishes (Section 1.2.1); the underlying workspace content itself remains saved as described in Section 5 until you delete it. We do not access, collect, or store direct messages, private comments, friend/follower lists, or any Meta user data beyond what is strictly necessary to publish content on your behalf.

1.2.5 Shopify-Specific Data

When you connect a Shopify store, ViralFarm acts as a Shopify Partner app and interacts with Shopify's Admin API on your behalf. The data we access is limited to what is necessary to generate social content from your catalog:

  • Shop & authorization data: shop domain (e.g. yourstore.myshopify.com), Shopify user/shop ID, granted scopes, and the encrypted OAuth access token.
  • Product data: product titles, descriptions, handles, images, product type, tags, price, availability, and related metadata returned by the Admin API.
  • HMAC & request metadata: Shopify provides signed HMAC parameters on OAuth redirects and webhook deliveries; we use these only to verify the authenticity of the request.

We do not request, access, or store Shopify orders, customers, checkout carts, payment details, fulfillment records, discount codes, draft orders, or any personally identifiable information about your shoppers. We do not use Shopify data to contact your customers, to market to them, or to build user profiles. Shopify product data is used solely to render previews inside your ViralFarm workspace and to help you create and publish social content you control.

ViralFarm complies with the Shopify App Store requirements, the Shopify API Terms of Service, and the Protected Customer Data requirements. We support Shopify's mandatory GDPR webhooks (customers/data_request, customers/redact, and shop/redact): on receipt of a redaction request we delete the corresponding Shopify records within 30 days, and we will provide any requested data export to the merchant for forwarding to their customer.

We do not collect or store: your social media or Shopify passwords, direct messages, private follower lists, shopper personal information (name, email, address, phone, order history), payment instruments, or any data beyond what is strictly necessary to provide the Service.

1.3 Information Collected Automatically

  • Usage Data: Pages visited, features used, actions taken, timestamps, and session duration.
  • Device & Browser Data: IP address, browser type, operating system, device type, and screen resolution.
  • Cookies & Similar Technologies: We use essential cookies for authentication and session management. We use Vercel Analytics, which sets no cookies, and PostHog, which stores a first-party identifier in a cookie and in your browser's local storage so that your page views and clicks can be tied to your visit and, once you sign in, to your account. See Section 8 for more details.

1.4 Information from AI Assistants & Connectors

AI models are involved in ViralFarm in two separate ways. First, ViralFarm itself sends your topic, source text, and template contract to Anthropic's and OpenAI's APIs to write post copy for every user (Section 3). Second, and separately, you can connect ViralFarm to your own AI assistant — Anthropic's Claude, OpenAI's ChatGPT, Muse, Cursor, or any other client that supports the Model Context Protocol (MCP) or our REST API — so that assistant can act in ViralFarm for you. This section describes the second case.

  • How you authorize an assistant: Either through an OAuth flow — the assistant registers as a client, you approve it while signed in to ViralFarm, and we issue it a ViralFarm API key named after that client (for example "Claude (OAuth)") — or by pasting an API key you created in Settings. We store a one-way hash of the key, its name, and when it was created and last used. Keys do not expire on their own; revoking one is how access ends.
  • Task inputs we receive: Only what the assistant passes to a ViralFarm tool or API endpoint for the task you asked it to do: the topic, link, or text to generate from; your choices of template, format, media pack, hook style, and similar options; images or videos it uploads for you; and scheduling instructions (which connected accounts, what time, and platform options such as live vs. drafts). Note that task text is whatever the assistant chooses to submit: it may include wording from your prompt or an excerpt of your conversation, and we receive and retain it as described below. What we do not have is independent access to your conversation: we cannot read the rest of your chat history, your other prompts, files you did not send to ViralFarm, or your identity or account details with the assistant provider.
  • What we return to the assistant: Exactly the fields the tools expose. Your profile: ViralFarm user id, email address, remaining credit balance, and the names of products you set up. Each connected social account: platform, username, display name, ViralFarm account id, and whether it is active. Template and media pack names. Each generated post: caption, title, template name, slide count, aspect ratio, and a link to view or edit it in ViralFarm. Each scheduled or published post: status, scheduled time, the accounts targeted, retry information, and per platform whether it was accepted, the platform's post id, and any error message the platform returned. We never return OAuth tokens, API keys, payment details, internal identifiers beyond those listed, or other users' data.
  • Retention of connector requests and logs: We retain the task-specific content submitted to ViralFarm; we do not keep an application log of individual tool calls, and we hold no conversation content beyond what was submitted in a task. What we keep in ViralFarm is: the time each API key was last used (until the key's record is deleted with your account); a record of each agent-initiated generation job (its inputs, such as the topic and options, and its status), retained alongside the posts it produced until those posts or your account are deleted, while a job that produced no post because it failed or never completed is deleted 30 days after it was created; and, on each post, which interface created it (web app or the named client). Infrastructure request logs kept by our hosting and database providers (Vercel, Railway, and Supabase) record the request path, timestamp, status, and client IP address — not request bodies — and are retained for no longer than 30 days. Web analytics are separate from connector traffic: Vercel Analytics stores only aggregated page-view data with no IP addresses.
  • Revoking access and deletion: Removing the ViralFarm connector inside an assistant stops that assistant from using the connection, but does not invalidate the API key it was issued — we do not offer clients a token-revocation endpoint, so the key remains valid until you revoke it. To revoke the key itself, go to Settings → API Keys; revocation there is immediate for every new request, whichever client holds the key. Posts and media the assistant already created remain in your workspace and can be deleted in ViralFarm like any other content. To delete your account and everything in it, email hi@myviral.farm from your account address (Section 5).
  • The assistant provider's policies apply to its side: Everything we return to an assistant becomes part of your conversation with it and is stored and used under the assistant provider's own privacy policy and terms (Section 7.5), not ours. We share nothing with the provider beyond the direct responses to its requests. ViralFarm does not use connector traffic to train AI models, sell it, or use it for advertising; whether the assistant provider uses your conversation for training is governed by that provider's policies and your settings with it, which we do not control.

2. How We Use Your Information

We use the information we collect for the following purposes:

  • Provide the Service: Generate, customize, export, schedule, and publish visual content to your connected social media accounts, and turn your Shopify product catalog into social posts, carousels, and scheduled content.
  • Account Management: Create and maintain your account, authenticate sessions, and process payments.
  • Scheduling & Publishing: Use OAuth tokens to schedule and publish posts to connected social media platforms at times you specify, and to fetch product listings from connected Shopify stores.
  • Improve the Service: Analyze usage trends, diagnose technical issues, and develop new features.
  • Communication: Send transactional emails (e.g., password resets, billing receipts), respond to support requests, and provide product updates (you may opt out of non-essential communications at any time).
  • Agent Access: Authenticate AI assistants and API clients you have authorized, execute the actions they request on your behalf, and attribute the resulting posts to the interface that created them.
  • Security & Compliance: Detect and prevent fraud, abuse, and security incidents; comply with legal obligations.

3. How We Share Your Information

We do not sell, rent, or trade your personal information. We share information only in the following limited circumstances:

  • Social Media & Commerce Platforms: When you schedule or publish a post, we transmit your content (text, images, video) and relevant metadata to the platforms you selected. When you connect a Shopify store, we read product listings from the Shopify Admin API to populate your workspace. All such calls are initiated by you and governed by each platform's own terms and privacy policy.
  • Processors acting on our instructions: These providers process personal data only to deliver their service to us, under business or API terms that limit use to that purpose:
    • Supabase (database, authentication, and file storage)
    • Stripe (payment processing)
    • Vercel (hosting and deployment)
    • Railway (media processing worker for video and image proxies)
    • PostHog (product analytics and error reporting: the pages you visit, the buttons you click, your account id, email and name so your activity is tied to your account, and performance data about AI generations such as the model used and response time — never the text you submit or the content generated for you)
    • Anthropic and OpenAI (AI text generation for every post ViralFarm writes, whether requested in the web app or through a connected assistant — the topic, source text or page, your instructions, and the template contract are sent to their APIs; under their API terms this data is not used to train their models)
  • Services operating under their own policies: These receive limited data and handle it under their own privacy policies rather than as our processors:
    • Pexels, Unsplash, and Google Custom Search (stock photos and image search when a post needs images) receive only the search keywords derived from your topic — never your account details or content.
    • Vercel Analytics (usage analytics) receives aggregated page-view and feature-usage events as described in Section 8.
  • AI Assistant Platforms: If you connect ViralFarm inside an AI assistant (Anthropic Claude, OpenAI ChatGPT, Muse, Cursor, or another MCP-compatible client), the requests that assistant sends us and the responses we return pass through that platform and are handled under its privacy policy (see Section 7.5). We share only the responses needed to complete the request. We do not receive personal data about you from the assistant provider beyond what is described in Section 1.4.
  • Legal Requirements: We may disclose information if required to do so by law, regulation, legal process, or governmental request.
  • Business Transfers: In the event of a merger, acquisition, or sale of assets, user information may be transferred to the successor entity, with notice provided to users.

4. Data Storage & Security

  • Data is stored on servers in the United States using Supabase (hosted on AWS) and Vercel.
  • Social platform OAuth access and refresh tokens are stored in our database, which our database provider encrypts at rest (AES-256), and are readable only by our server-side code — never by browsers or by connected assistants.
  • ViralFarm API keys used by AI assistants and other clients are stored only as one-way hashes; the raw key is shown once at creation and cannot be recovered by us.
  • All data is transmitted over HTTPS/TLS.
  • Server-side data access is restricted to our application and service roles with row-level access controls, and API requests are logged for security and rate limiting.
  • Passwords (when applicable) are hashed and salted; we never store plaintext passwords.

While we employ commercially reasonable measures to protect your information, no system is 100% secure. We cannot guarantee absolute security but will notify affected users promptly in the event of a data breach.

5. Data Retention & Deletion

  • Account Data: Retained for as long as your account is active. To delete your account, email hi@myviral.farm from your account address; we delete or anonymize your personal data, content, connected-account tokens, and API keys within 30 days, except where retention is required by law.
  • Saved Workspace Content: Generated posts, uploaded media, media collections, rendered post images and videos, and cached transcoded copies of your videos are kept until you delete them or your account is deleted.
  • Temporary Publishing Copies: Files held only to transmit a post to a platform are discarded when the publish attempt finishes (Section 1.2.1).
  • OAuth Tokens: Erased from our database immediately when you disconnect a social media account (and revoked with the platform where it offers a revocation API, currently TikTok), when you uninstall the ViralFarm app from Shopify, or when your ViralFarm account is deleted. For Shopify, uninstalling the app triggers the app/uninstalled webhook; we delete the store's OAuth token immediately and purge cached product data within 48 hours.
  • Shopify Shop & Customer Redaction: On receipt of Shopify's shop/redact webhook (sent ~48 hours after uninstall) we permanently delete all remaining data for that shop. On receipt of customers/redact we delete any data associated with that customer identifier (note: we do not retain Shopify customer PII, so in most cases this is a no-op). customers/data_request events are logged and forwarded to the merchant.
  • API Keys & Agent Authorizations: Kept until you revoke them in Settings → API Keys or delete your account. A revoked key is marked revoked immediately and can no longer be used; its record is deleted with your account. Records of agent-initiated generation jobs are retained with the posts they produced; jobs that produced no post are deleted 30 days after creation.
  • Logs & Analytics: Aggregated, anonymized usage data may be retained indefinitely for analytics and product improvement.

6. Your Rights & Choices

Depending on your jurisdiction, you may have the following rights:

  • Access: Request a copy of the personal data we hold about you.
  • Correction: Request correction of inaccurate or incomplete data.
  • Deletion: Request deletion of your personal data ("right to be forgotten").
  • Portability: Request a machine-readable export of your data.
  • Restrict Processing: Request that we limit how we use your data.
  • Withdraw Consent: Where processing is based on consent, you may withdraw it at any time.
  • Opt Out of Marketing: Unsubscribe from marketing emails at any time via the link in the email or your account settings.
  • Disconnect AI Assistants: Revoke any assistant's or client's API key at any time from Settings → API Keys; revocation is immediate for new requests. Removing the connector inside the assistant stops that assistant using it but does not invalidate the key, so revoke it in ViralFarm as well (Section 1.4).
  • Disconnect Social Accounts: Revoke the Service's access to any connected social media account at any time from your account settings or from the social platform's own app permissions page.

You can also revoke ViralFarm's access to your data directly through each platform's security settings, including: Google Security Settings (YouTube), Facebook Business Integrations (Instagram, Facebook, Threads), LinkedIn Permitted Services, TikTok Security Settings, Pinterest App Permissions, X (Twitter) Connected Apps, and your Shopify admin under Settings → Apps and sales channels → ViralFarm → Uninstall.

To exercise any of these rights, contact us at hi@myviral.farm. We will respond within 30 days (or sooner as required by applicable law).

6.1 California Residents (CCPA)

If you are a California resident, you have the right to know what personal information we collect and how it is used, request deletion of your personal information, and opt out of the sale of personal information. We do not sell personal information. To exercise your CCPA rights, email hi@myviral.farm.

6.2 European Economic Area & UK (GDPR)

If you are located in the EEA or UK, our legal bases for processing are: (a) your consent, (b) performance of a contract (providing the Service), (c) legitimate interests (improving the Service, security), and (d) compliance with legal obligations. You may lodge a complaint with your local data protection authority.

7. Third-Party Platform Policies

When you use the Service to interact with third-party social media platforms, your use is also subject to those platforms' terms and privacy policies. We encourage you to review:

By using our YouTube integration, you are also bound by the YouTube Terms of Service and the Google Privacy Policy.

We access platform data solely through official APIs and within the scope of permissions you grant. We do not scrape, crawl, or otherwise collect data outside of authorized API access.

7.2 Google API Services — Limited Use Disclosure

ViralFarm's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

7.3 Platform-Specific Data Use Limitations

Data obtained from each third-party platform's API is used exclusively to provide the Service to the individual user who authorized access. Specifically:

  • Data from one user's connected social account is never combined, aggregated, or cross-referenced with data from another user's account.
  • Platform API data is not used for advertising, ad targeting, data brokerage, market research, user profiling, or any purpose other than performing the publishing and scheduling actions requested by the authorizing user.
  • Platform API data is not sold, licensed, or shared with any third party for their independent use.
  • Platform API data is not used to train machine learning or AI models.
  • We access only the minimum data and permissions necessary to publish content and report back the publishing status to the user.
  • We do not read or store TikTok content (videos, comments, followers, analytics). TikTok profile identifiers and the token needed to publish are retained only while the account is connected; publishing status metadata is retained with the post record.

These restrictions apply to all supported platforms, including but not limited to: Meta (Instagram, Facebook, Threads), Pinterest, LinkedIn, TikTok, X (Twitter), YouTube, and Shopify.

7.4 Shopify — App Store & Protected Data Compliance

ViralFarm's Shopify integration is built and maintained in accordance with the Shopify App Store requirements checklist, the Shopify API Terms of Service, the Shopify Partner Program Agreement, and the Protected Customer Data requirements. Specifically:

  • We request the minimum necessary scopes (product read access) and do not request access to orders, customers, checkouts, or payment data.
  • All Shopify Admin API calls are authenticated using a per-shop encrypted access token and are made over HTTPS/TLS.
  • All incoming Shopify webhooks are HMAC-verified against our shared secret before any action is taken.
  • We implement Shopify's mandatory compliance webhooks: customers/data_request, customers/redact, and shop/redact.
  • Shopify product data is used solely to render previews and to help the authorizing merchant generate social content — it is never sold, rented, shared with other merchants, used to build competing products, or used to train AI models on behalf of third parties.

7.5 AI Assistant Platform Policies

When you use ViralFarm through an AI assistant, your conversation with that assistant — including the requests it sends to ViralFarm and the responses we return — is also governed by the assistant provider's terms and privacy policy. Please review the policy of the provider you use, for example the Anthropic Privacy Policy (Claude), the OpenAI Privacy Policy (ChatGPT), Muse's privacy policy, or the policy of any other MCP-compatible client. ViralFarm is not responsible for how an assistant provider stores or uses your conversation.

Our MCP server and REST API expose a fixed set of tools (listing your accounts and templates, generating posts, uploading media, and scheduling, cancelling, or retrying posts). An assistant can only act within the permissions of the ViralFarm account that authorized it, and every publish action is carried out under your instruction to that assistant.

8. Cookies

We use the following types of cookies:

  • Essential Cookies: Required for authentication, session management, and security. Cannot be disabled.
  • Analytics: Vercel Analytics helps us understand how the Service is used (e.g., page views, feature usage). It sets no cookies and stores no IP addresses; you may block it with a content blocker.
  • Product Analytics (PostHog): PostHog sets a first-party cookie and uses local storage to recognise your browser across page views, so we can see which pages you visit and which buttons you click, and, once you sign in, link that activity to your account. We use this to find where people get stuck and to fix errors. You may block it with a content blocker; the Service keeps working without it.

We do not use advertising cookies, and we do not share analytics data with advertisers.

9. Children's Privacy

The Service is not directed to individuals under the age of 16. We do not knowingly collect personal information from children under 16. If we learn that we have collected personal data from a child under 16, we will delete it promptly. If you believe a child has provided us with personal information, please contact us at hi@myviral.farm.

10. International Data Transfers

ViralFarm is operated from the United States, and your information is stored and processed there: our database and file storage run on Supabase (hosted on AWS), and our application runs on Vercel (see Section 4). The processors listed in Section 3 are U.S.-based companies. If you use ViralFarm from outside the United States, including from the EEA or the UK, your information is transferred to and processed in the United States. We ensure appropriate safeguards are in place for these transfers, including standard contractual clauses where required by applicable law, alongside the security measures described in Section 4. When you use ViralFarm through an AI assistant, that assistant's provider handles your requests under its own policy, which may involve processing in other countries (see Section 7.5).

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page and updating the "Last Updated" date. For significant changes, we may also notify you via email or an in-app notification. Your continued use of the Service after any changes constitutes acceptance of the updated policy.

12. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

  • Email: hi@myviral.farm (privacy questions, data access and deletion requests, and security reports)
  • Website: www.myviral.farm

© 2026 MyViral.Farm. All Rights Reserved.

Annie Yang T/A MyViral.Farm

Terms of Service