What we store, and what we never see
UViral is run by TheXMedia Inc. from Ontario, Canada. This page says exactly what the product keeps about you, who else touches it, and how to get rid of it. It describes the product as it is built today, not as a category of software in general.
In effect from 31 August 2026
The short version
- We store the email and password you sign up with, the handles you choose to watch, and the scripts you generate.
- We set one cookie. It keeps you signed in. There is no analytics cookie, no advertising pixel and no third-party tracker anywhere on this site or in the product.
- We never see your card. Stripe takes the payment and we store only the identifiers it hands back.
- Deleting your account deletes your data. We do not keep a shadow copy.
- We do not sell your data, and we do not share it for advertising.
What we collect, and why each piece exists
Every field below is one the product actually reads. Nothing is collected speculatively for a feature that might arrive later.
- Email address
- Your login, and the only way we can reach you about billing or a problem with your account.
- Password
- Stored as a bcrypt hash, never as text. We cannot read it, recover it or tell you what it is.
- Name
- Optional. Used to address you in the product. Leave it blank and nothing breaks.
- Your own handle
- Read once during onboarding to work out your niche, which sets the view threshold your board uses.
- Your public profile snapshot
- Name, photo, follower, following and post counts, taken from that same read and shown back to you so you can confirm we found the right account.
- Handles you track
- The accounts you asked us to watch, so your board has something on it.
- Scripts you generate
- Kept so you can find them again under Scripts, and so a row you have already written from is marked as such on the board.
- Billing identifiers
- Your Stripe customer and subscription IDs, the status Stripe reports, and when the paid period ends. These decide what your plan lets you do.
- Server logs
- Our host records requests, including IP addresses, as part of running the service. We do not build profiles from them.
What we never have
- Your card number. The payment form is Stripe’s and the card goes straight to them. It does not pass through our servers.
- Your Instagram or Facebook password. We never ask for it and there is nothing in the product that could accept it. We read public profiles the way any visitor can.
- Your direct messages, drafts, insights or anything behind your login on any platform. We are not connected to your account and cannot post as you.
- Your readable password. A hash is not reversible. If you lose it you reset it; nobody here can look it up.
The one cookie
The product sets a single cookie, uviral_session. It holds a signed token that says which account you are, so you are not asked to log in on every page. It is marked HttpOnly, so page scripts cannot read it, and SameSite Lax, so it is not sent from other sites. It lasts 30 days, and logging out deletes it.
That is the whole list. This site loads no analytics, no heatmaps, no session recording and no advertising tags, which is also why there is no cookie banner to dismiss.
Who else processes your data
Running the product means other companies touch parts of it. This is all of them, and what each one does. If we add a vendor, it appears here in the same release.
- Vercel
- Hosts this site and the product. Sees request logs, including IP addresses. Their privacy policy.
- Neon
- Runs the Postgres database that holds your account, your tracked handles and your scripts. Their privacy policy.
- Stripe
- Takes the payment and holds the card. We never receive or store your card number. Their privacy policy.
- Apify
- Reads public Instagram and Facebook profiles and reels on our behalf. Their privacy policy.
- Sarvam AI
- Turns the audio of a public reel into a word-for-word transcript. Their privacy policy.
- Anthropic
- Writes the script and the hook breakdown from a transcript. Your prompts are not used to train its models. Their privacy policy.
Most of these run in the United States, so your account data is stored and processed outside Canada and is subject to the laws of the country it sits in, including lawful access requests made there. Signing up means you accept that transfer. If it is a problem for you, tell us before you subscribe rather than after.
Creators in the library who never signed up
The board is built from public posts by accounts our users chose to watch. Those creators are not UViral users and did not agree to anything. We hold what is already public about a post: the handle, the caption, the view, like and comment counts, the link, and a transcript of what is said out loud in it.
We do not collect private or contact details about them, we do not republish their video, and we do not present anyone as endorsing this product. If you are a creator and you want your account out of the library, email team@thexmedia.com from an address or handle we can tie to the account, and we will remove it and stop reading it.
What the AI vendors do and do not keep
Transcription and script generation send the audio or transcript of a public reel to the vendors named above. Your own account details are not part of that request, and your content is not used to train their models under the business terms we are on.
A generated script is stored against your account so you can find it again, and the transcript of a public reel is cached once for everyone rather than re-fetched per user.
How long we keep things
- While your account is open
- Everything above, so the product works.
- When you delete your account
- Your account, tracked handles, scripts and style profile are deleted with it. This is immediate and cannot be undone.
- Billing records
- Stripe keeps the payment history it is required to keep. We cannot delete records held in their system on their own retention clock.
- The public library
- Rows about public reels stay, because they are not personal data about you and other users depend on them. Nothing in them identifies you as having viewed a reel.
- Server logs
- Held on our host’s own schedule, in the ordinary course of running a service.
Your rights
Canadian privacy law, PIPEDA, gives you the right to see what we hold about you, correct it, and withdraw consent. You can do most of it yourself: your account page shows what we have, and deleting the account removes it.
For anything the product does not cover, email team@thexmedia.com. We answer within 30 days, which is what the law allows. If you are in the UK or the EU, the same requests work; write to the same address. If we get it wrong, you can complain to the Office of the Privacy Commissioner of Canada.
Security, stated plainly
Passwords are hashed with bcrypt. The session token is signed and cannot be edited by the browser holding it. Traffic runs over HTTPS. Admin access inside the product is a role recorded on the account, and every privileged action is written to an audit log before it happens.
None of that is a guarantee. No service can promise it will never be breached, and anyone who does is telling you something they cannot know. If we find a breach that affects you, we will tell you and the regulator, because we are required to.
Children
UViral is a paid tool for people running social accounts, and is not intended for anyone under 16. We do not knowingly hold data about children. If a child has signed up, email us and we will remove the account.
Changes to this policy
When this changes, the date at the top changes with it. If a change actually affects what we collect or who receives it, we will email account holders rather than quietly reposting the page.
Reaching a person
TheXMedia Inc., Ontario, Canada. Email team@thexmedia.com. There is no chat widget and no phone queue; that address reaches the people who built this.