Security
Data, hosting, payments, deletion.
What lives where, who can touch it, and how to remove it.
Hosting
Application, database, and generated video files all live on Supabase in the EU (Frankfurt region). Static assets and serverless functions run on Vercel.
Database
PostgreSQL via Supabase. Row-Level Security enabled on every public table. Service-role keys never leave the server bundle.
Encryption
TLS 1.2+ in transit (HSTS preload, max-age two years). Disk encryption at rest via Supabase Storage.
Authentication
Email magic-link and OAuth (Google, Apple, Telegram). CSRF protection enforced at the edge; session cookies are HttpOnly and SameSite=Lax. We never store passwords.
Payments
Stripe Checkout (PCI-DSS Level 1). We never see your card number — Stripe returns a customer ID we associate with your account. Webhooks are signature-verified.
Content security
Strict CSP (script-src restricted to first-party plus Stripe, Telegram, Cloudflare Turnstile, Vercel analytics). X-Frame-Options SAMEORIGIN. Permissions-Policy blocks camera, microphone, and geolocation by default.
AI bot access
Robots policy explicitly allows GPTBot, ClaudeBot, PerplexityBot, OAI-SearchBot, Google-Extended, Applebot-Extended, and CCBot for marketing pages. Authenticated routes (/dashboard, /api, etc.) are disallowed for every crawler.
Generated content ownership
You own every clip you approve. We do not retrain models on your generated content. We do not redistribute your videos. We do not reveal your discovery sources to other accounts.
Backups
Supabase point-in-time recovery covers the last 7 days on Pro tier. Generated video files are durable in Supabase Storage; deleted files are unrecoverable after the soft-delete window.
Account deletion
Settings → Account → Delete account removes your profile, scheduled posts, reel items, generated videos, Stripe customer reference, and authentication record. The action is irreversible and completes synchronously.
Incident contact
Email security@viralgen.ai with a clear description and a contact method. We acknowledge within one business day.
Sub-processors
Stripe (payments), Supabase (database + storage), Vercel (hosting + edge runtime), Apify and HikerAPI (Instagram / TikTok discovery scrapers), Wavespeed (AI inference), Cloudflare Turnstile (bot mitigation).
Few minutes. A month of content.
What took a week now takes a few minutes.
Finding the reel, making it, cleaning it, scheduling it. That used to be days of work across four tools and few employees. Now you open the app, approve, and a month of content delivers itself. In few minutes.
- From €49/mo
- No prompt-engineering
- Cancel anytime
- No long-term contract
