Privacy

PublishedMay 20th, 2025
UpdatedSeptember 26th, 2026

Last updated: September 26, 2026

This Privacy Policy explains which personal data we process in connection with the viral.app website and the viral.app SaaS service, for which purposes, on which legal basis, and which rights you have.

1. Controller

The controller for the processing described here is:

FMD Labs GmbH
Ernst-Haeckel-Platz 5/6
07745 Jena
Germany

Commercial register: Local Court (Amtsgericht) of Jena, HRB 523255
Represented by its managing directors: Felix Meier, Mike Schneider, Dennis Zollmann
Email: hello@viral.app
Phone: +49 151 22821132

2. Hosting and Server Log Files

Our website and the service run on Vercel Inc. (USA) for the web applications and on our own servers at Hetzner Online GmbH (data centers in Germany and Finland) for databases, data processing, real-time chat, and caching. We use Cloudflare, Inc. (USA) for object storage (for example, uploaded files, media, and backups) and to protect access to internal services. We have data processing agreements pursuant to Art. 28 GDPR with these providers; transfers to the USA are based on the EU-U.S. Data Privacy Framework.

When you visit our pages, our servers automatically process the following data (server log files): IP address, date and time of access, page or file requested, amount of data transferred, browser type and version, operating system, and referrer URL. The processing is based on Art. 6 (1)(f) GDPR; our legitimate interest lies in the technical provision, stability, and security of the service. Log files are deleted as soon as they are no longer required for these purposes, usually after 30 days at the latest, unless they are needed to investigate specific security incidents.

3. Cookies and Embedded Content

We use cookies and similar technologies (for example, local storage in your browser). We use strictly necessary cookies, for example for sign-in and session management (sessions expire after 7 days without use), language settings, invitation links, and securing sign-in flows with connected services, on the basis of Sec. 25 (2) of the German Telecommunications Digital Services Data Protection Act (TDDDG) and Art. 6 (1)(b) or (f) GDPR. We also use cookies and similar technologies for analytics, attribution, and marketing purposes; Section 4 describes which services these are and on which legal basis we use them.

You can prevent cookies from being stored in your browser settings, delete stored cookies at any time, and block analytics and marketing technologies through your browser settings or with browser extensions.

Some pages embed third-party content, such as posts from social media platforms (for example, TikTok, Instagram, YouTube, X, LinkedIn, Facebook, Pinterest) or our booking calendar (see Section 12). When such content loads, the respective provider receives your IP address and browser information and may set its own cookies. The legal basis is our legitimate interest in presenting our content attractively and in offering appointment booking directly on our website (Art. 6 (1)(f) GDPR).

4. Web Analytics, Attribution, and Marketing

We use the following services to measure the use of our website and application and the success of our advertising, and to advertise our service. The legal basis is our legitimate interest (Art. 6 (1)(f) GDPR); you can object at any time (Section 19), for example by email to hello@viral.app, and block these technologies in your browser (Section 3). Transfers to the USA are based on the EU-U.S. Data Privacy Framework.

  • Meta (Meta Platforms Ireland Ltd., Dublin, Ireland): Meta Pixel, Conversions API, and Custom Audiences, including hashed email address and name, user ID, IP address, and browser and click identifiers. We are jointly responsible with Meta for the collection and transmission (Art. 26 GDPR).
  • Google Ads (Google Ireland Limited, Dublin, Ireland) and Reddit (Reddit, Inc., USA): conversion tracking via tag or pixel and server-side events such as sign-ups, checkouts, and subscriptions, with click identifiers and, for Reddit, hashed email address and user ID.
  • Campaign attribution and affiliate program: we store campaign parameters, landing page, and referrer in cookies for up to 90 days and link them to your account when you sign up; a cookie from Affonso (ZASolution, Fellbach, Germany) records for up to 60 days which partner referred you. If you take part in the affiliate program yourself, we share your name and email address with Affonso (Art. 6 (1)(b) GDPR).
  • PostHog (PostHog Inc., USA, EU cloud): usage analytics and, in the application, session recordings with form input masked, linked to your account and organization.
  • Sentry (Functional Software, Inc., USA, processing in Germany): error diagnostics including IP address and user ID.

5. Registration, Customer Account, and Contract Performance

When you sign up for viral.app or use the service, we process the data you provide: name, business email address, company details, login data, and contract, plan, and billing data. The processing takes place to conclude and perform the contract (Art. 6 (1)(b) GDPR). Where contact persons of a business customer are concerned, the processing is based on our legitimate interest in communicating with our business customers (Art. 6 (1)(f) GDPR). Providing the registration and contract data is necessary to conclude and perform the contract; without it, we cannot conclude or perform the contract.

For sign-in, we offer a sign-in link or one-time code by email, passkeys, and sign-in with a Google account (Google Ireland Limited); with Google sign-in, we receive the email address and basic profile data stored with Google (Art. 6 (1)(b) GDPR). You can optionally enable browser push notifications; they are delivered through your browser's push service (for example, Google, Mozilla, Apple) on the basis of your consent (Art. 6 (1)(a) GDPR), which you can withdraw at any time in your browser settings.

If you connect viral.app to third-party applications through our programming interfaces (for example, with an API key or by connecting an AI assistant), we transmit the requested data to that application at your request. The respective provider is responsible for further processing there.

6. Research on Business Customers at Registration

When you create an organization, we research publicly available information on the internet based on your name, email address, company, and country (using the search service Firecrawl, USA) and have a short summary created from it (using our AI service, see Section 10). We use the result internally to better serve new business customers and share it in our internal communication tool Slack. The legal basis is our legitimate interest in serving and qualifying business customers (Art. 6 (1)(f) GDPR). You can object to this processing at any time (see Section 19).

7. UGC and Creator Analytics (Platform Features)

The core feature of viral.app is the analysis of publicly available content and metrics from social media platforms (for example, TikTok, Instagram, YouTube, Facebook, Snapchat), for example on videos, accounts, and their performance. This may involve processing personal data of creators (for example, username, profile information, published content, reach and engagement metrics). This data comes from publicly accessible sources of the respective platforms; we use specialized service providers to retrieve it.

Where we process this data on behalf of our customers (for example, tracking the accounts and campaigns selected by the customer), the respective customer is the controller under data protection law and we act as processor on the basis of our Data Processing Agreement, which also contains the full description of the processing. This also applies to creator profiles and compensation data that our customers create in viral.app; to that extent, informing the creators concerned pursuant to Art. 13 and 14 GDPR is the responsibility of the respective customer as controller. Where we process data under our own responsibility (for example, cross-customer features such as trend and discovery views based on public data), we rely on our legitimate interest in providing and improving the service (Art. 6 (1)(f) GDPR). We keep customer environments strictly separate and do not use a customer's non-public data (for example, tracked accounts, prompts, search queries) to generate results for other customers. This does not affect the use of aggregated and anonymized data without any personal reference, from which no conclusions can be drawn about individual customers or creators, to operate and improve the service.

8. Creator Accounts and Creator Marketplace

Creators aged 18 or older can create their own account, maintain a profile, apply for jobs posted by brands, communicate with brands, and receive payouts. For this, we process the information you provide, in particular name, email address, profile photo, date of birth, gender, phone number, address, country, languages, topics and content formats, education, connected social media accounts with their public metrics, selected videos, as well as applications and messages. The legal basis is the performance of our user relationship with you (Art. 6 (1)(b) GDPR).

Brands that use viral.app can see your profile in the creator search, in particular name, age (calculated from your date of birth), gender, languages, country, topics, social media accounts with metrics, and selected videos. A brand only receives your address and further contact details once you work with it or release them yourself. To suggest suitable jobs to you and suitable creators to brands, we automatically match profiles and jobs and have short explanations of the fit created by our AI service (see Section 10); we automatically rank applications for the respective brand by how well they fit the job (for example, country, age, languages, topics, and reach); the decision on any collaboration is made solely by you and the respective brand. The legal basis is the performance of the user relationship (Art. 6 (1)(b) GDPR) or our legitimate interest in a functioning marketplace (Art. 6 (1)(f) GDPR).

We store messages and files you exchange with a brand on our servers; they are visible to the brand involved and may be analyzed by its AI assistant (see Section 10). If you allow a brand to use your content for ads (for example, via TikTok or Meta), the information required for this is transmitted to the respective platform. To the extent we or the payout service provider are legally required to report creators' earnings to tax authorities (German Platform Tax Transparency Act implementing the EU DAC7 directive), we process and transmit the necessary information, such as tax identification number, date of birth, address, and earnings (Art. 6 (1)(c) GDPR). Where we enable ratings, they are visible to the users involved. You can delete your creator account yourself in your account settings, unless an ongoing collaboration or payout history prevents this; in that case, please contact hello@viral.app.

9. Creator Payouts and Disclosure to Payment Service Providers

viral.app can calculate payout amounts for creators based on performance data. When our customer approves a payout, we transmit the data required for it (for example, name or user ID of the payee, email address, payout amount, description, and underlying performance data) to the payout service provider chosen by the customer, currently Talentir GmbH (Talentir LLC), Stockerstrasse 38, 8002 Zurich, Switzerland (CHE-146.889.750). Our customer sets up the connection via an interface it authorizes; the binding payout order is placed in the payout service provider's environment. The legal basis is the performance of the contract with our customer (Art. 6 (1)(b) GDPR) or our legitimate interest in handling the payout processes commissioned (Art. 6 (1)(f) GDPR).

The payout service provider processes the data on the basis of its own contractual relationship with the customer or the payee, partly on behalf of the customer and partly under its own responsibility (for example, for identity and anti-money-laundering checks and the execution of payments); its privacy policy applies. There is an adequacy decision of the European Commission for transfers to Switzerland (Art. 45 GDPR).

10. AI-Powered Features

For AI-powered features, we use Google's Gemini API on the paid tier; the contracting party is Google Cloud EMEA Limited, 70 Sir John Rogerson's Quay, Dublin 2, Ireland. These features include in particular:

  • automated tagging and analysis of videos based on criteria configured by the customer (video content including the audio track),
  • our assistant (Copilot), which processes data of the respective organization on request, including uploaded files and messages with creators,
  • extracting tracking lists from uploaded files,
  • matching creator profiles and jobs, including short explanations of the fit,
  • summarizing the research on new business customers (Section 6).

Google processes the transmitted data as our processor and does not use it to train its models on the paid tier. To detect abuse, Google stores inputs and outputs for up to 55 days. Persons are not identified on the basis of biometric characteristics. Data may be processed in third countries, in particular the USA; the transfer is based on the EU-U.S. Data Privacy Framework. Where the processing takes place on behalf of our customers, Section 7 applies; otherwise, the legal basis is the performance of the contract (Art. 6 (1)(b) GDPR) or our legitimate interest in providing the features efficiently (Art. 6 (1)(f) GDPR). Payouts are calculated by fixed rules, without AI.

11. Subscription Payment Processing

For subscription billing, we use Polar Software, Inc., 3500 South DuPont Highway, Dover, DE 19901, USA, as merchant of record. Polar is your contractual partner for the purchase and payment process and processes your payment data as an independent controller; Polar's privacy policy applies in this respect. We send Polar your name, email address, user and organization ID, IP address, and information about the origin of the order. We ourselves do not receive or store complete payment data, only order and billing information (Art. 6 (1)(b) GDPR). Transfers to the USA are based on the EU Standard Contractual Clauses.

12. Support, Communication, Appointment Booking, and Video Calls

When you contact us (for example, by email or via our support chat, which we run with self-hosted software on our own infrastructure), we process your information to handle your request; in the application's support chat, we also transmit information about your account, your organization, and your plan for this purpose. The legal basis is Art. 6 (1)(b) GDPR where the request concerns a contractual relationship, and otherwise Art. 6 (1)(f) GDPR (legitimate interest in responding to inquiries).

We send transactional emails (for example, sign-in links, system notifications) with email software we run on our own servers at Hetzner Online GmbH, delivered through Amazon Simple Email Service (Amazon Web Services EMEA SARL, Luxembourg; data center in Frankfurt, Germany). While we switch over, some of them are still sent via Resend (Plus Five Five, Inc., USA). We send product emails and our newsletter via Loops (Astrodon Inc., USA). Transfers to the USA are based on the EU-U.S. Data Privacy Framework. Business accounts receive our newsletter about viral.app and creators receive emails about matching jobs and their profile (Art. 6 (1)(f) GDPR, Sec. 7 (3) of the German Act Against Unfair Competition, UWG); you can object at any time via the unsubscribe link in every email or at hello@viral.app, without any costs other than the transmission costs at the basic rates.

To book demo appointments, we embed the booking calendar of Cal.com (Cal.com, Inc., USA). When you book an appointment, Cal.com and we process your name, email address, the information you enter in the booking form, and the appointment; we transmit the booking to our system to prepare the call. The legal basis is the performance of pre-contractual measures at your request (Art. 6 (1)(b) GDPR).

We hold calls with prospects, customers, and partners via Google Meet (Google Ireland Limited) and record them with Google Meet's note-taking feature and Circleback (Circleback AI, Inc., USA), which also create transcripts and summaries, to document what was discussed and agreed (Art. 6 (1)(f) GDPR; transfers to the USA are based on the EU-U.S. Data Privacy Framework). If you would rather not be recorded, just let us know; we delete recordings, transcripts, and summaries once they are no longer needed for the business relationship.

If you report illegal content in the service to us (see our Terms of Service and Creator Terms of Use), we process your information, the reported content, and the communication with those involved in order to review the report and decide on measures. The legal basis is compliance with our obligations under the Digital Services Act (Art. 6 (1)(c) GDPR) or our legitimate interest in a safe service (Art. 6 (1)(f) GDPR).

13. Social Media Profiles

We maintain company profiles on X, LinkedIn, Instagram, TikTok, and YouTube. When you visit these profiles, the respective platform processes your data under its own responsibility in accordance with its privacy policy. Where the platforms provide us with aggregated page statistics, we are jointly responsible with them (Art. 26 GDPR); the platforms provide the essential terms of these arrangements. In addition, we process your messages and comments to us in order to respond to them (Art. 6 (1)(f) GDPR).

14. Retention Periods

We only process personal data for as long as necessary for the respective purposes. In detail:

  • Account and organization data is stored for as long as your account exists. After a paid contract ends, we make your data available for export upon request made within 30 days. You can request the deletion of your account at any time; creators can also delete their account themselves (Section 8).
  • Billing-related data is retained in accordance with statutory retention periods (6, 8, or 10 years pursuant to Sec. 257 of the German Commercial Code (HGB) and Sec. 147 of the German Fiscal Code (AO)).
  • Security logs of actions in the service (for example, user ID, IP address, action) are stored for 365 days; details are trimmed after 90 days.
  • Sign-in links and one-time codes are valid for 5 minutes; sessions expire after 7 days without use.
  • Internal processing events are deleted after 2 days, generated data exports after 7 days, and media temporarily stored for AI analysis usually after 30 days.
  • Cookies are stored for the periods stated in this policy, attribution cookies for up to 90 days.
  • Newsletter data is stored until you unsubscribe.

15. Recipients and Processors

We only disclose personal data as described in this policy or where there is a legal basis for it. Categories of recipients are in particular: hosting and infrastructure providers, service providers for retrieving public platform data, payout service providers, providers of AI and research services, payment processors (merchant of record), email delivery providers, communication and collaboration tools for internal workflows, and analytics and marketing providers. Where these service providers process data on our behalf, data processing agreements pursuant to Art. 28 GDPR are in place.

16. Transfers to Third Countries

Where we transfer data to countries outside the EU or EEA, this is done on the basis of an adequacy decision of the European Commission (for example, Switzerland; the USA under the EU-U.S. Data Privacy Framework for certified providers) or on the basis of the EU Standard Contractual Clauses pursuant to Art. 46 (2)(c) GDPR, supplemented by any necessary additional measures. We provide details for the respective services; we will provide a copy of the safeguards upon request.

17. Data Security

We take appropriate technical and organizational measures pursuant to Art. 32 GDPR to protect your data against loss, misuse, and unauthorized access, and we review them regularly, taking into account the state of the art, the costs of implementation, and the nature, scope, and purposes of the processing. Data transmitted between your browser and our website or the service is encrypted (TLS).

To protect the service and its users against attacks, misuse, and fraud, for example unauthorized access, automated extraction, multiple or shared accounts, or manipulated metrics, we evaluate account, usage, and log data as well as payment and payout details available to us, and may review accounts that recognizably belong together. The legal basis is Art. 6 (1)(f) GDPR; our legitimate interest lies in the security and integrity of the service and in preventing fraud. Measures such as blocking an account are decided by a person.

18. Your Rights

You have the following rights with regard to your personal data:

  • Access (Art. 15 GDPR)
  • Rectification (Art. 16 GDPR)
  • Erasure (Art. 17 GDPR)
  • Restriction of processing (Art. 18 GDPR)
  • Data portability (Art. 20 GDPR)
  • Objection (Art. 21 GDPR, see Section 19)
  • Withdrawal of consent with effect for the future (Art. 7 (3) GDPR)

An informal message to hello@viral.app is sufficient to exercise your rights. If your request concerns data that we process on behalf of a customer (Section 7), we will forward it to the respective customer. You also have the right to lodge a complaint with a data protection supervisory authority (Art. 77 GDPR); the authority responsible for us is the Thuringian State Commissioner for Data Protection and Freedom of Information (Thüringer Landesbeauftragter für den Datenschutz und die Informationsfreiheit), Postfach 900455, 99107 Erfurt, Germany.

19. Right to Object (Art. 21 GDPR)

Where we process data on the basis of legitimate interests (Art. 6 (1)(f) GDPR), you have the right to object to the processing at any time on grounds relating to your particular situation. We will then no longer process the data unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms, or the processing serves the establishment, exercise, or defense of legal claims. You can object to processing for direct marketing purposes at any time without giving reasons.

20. Changes to This Privacy Policy

We update this Privacy Policy when the legal situation, the service, or the data processing changes. The current version is always available on our website; we also inform registered users of material changes by email.