Legal
Privacy Policy
The short version: we hold a wallet address, whatever you type into a project, and your generated files for seven days. We ask for no name, no phone number and no document, and an email only if you volunteer one.
Last updated 4 August 2026
1. What we never collect
Stating this first, because most of the value here is in the absence.
- No password. You log in by signing a message with your wallet. We have nothing to leak.
- No name, address, phone number or identity document. We never ask, and there is nowhere to enter them.
- No payment instrument. No card, no bank details. Payment is a transfer you make from your own wallet.
- No content from your social accounts. If you enter a handle it decides which format we generate for. We do not fetch or read your posts, followers or metrics.
- No third party analytics, no advertising pixels, no cross site tracking. The site loads nothing from another company's servers. You can verify this in your browser's network panel.
2. What we do store
| Data | Why | How long |
|---|---|---|
| Wallet address | It is your account identity | Until you ask us to delete it |
| Email, if you enter one | To warn you when something fails | Until you remove it |
| Project details you type: name, ticker, niche, pitch, handles | To shape what gets generated | Until you delete the project |
| Your briefs and the optimised prompts | To generate, and to reproduce a clip you report as wrong | Until you ask us to delete them |
| Reference images you upload | To start a video from them | 7 days |
| Generated videos and images | So you can download them | 7 days, then permanently deleted |
| Quota counters and job history | To bill correctly and to return quota when we fail | Until you ask us to delete the account |
| Payment transaction hashes | To confirm a plan was paid | Until you ask us to delete the account |
Our server is a place your files pass through, not an archive. Deletion after seven days is not a courtesy: it is also why we cannot hand over what we no longer have.
3. What is public whether we like it or not
Your payment is a blockchain transaction. It is permanently public, linked to your wallet address, and neither we nor you can delete it. Anyone can see that your wallet paid ours. If that matters to you, pay from a wallet you do not mind being seen.
4. Who else touches your data
Generating requires sending your prompt to machines we rent. Specifically:
- RunPod runs the GPUs. Your prompt and any reference image go there for the duration of the job. We run our own model image on their hardware; they do not train on anything.
- Groq receives your brief so an open weight language model can rewrite it into a prompt. It is text only: no wallet address, no email, no project identity.
- Hostinger hosts the server that holds the database and the files for seven days.
That is the whole list. We do not sell data, we do not share it for advertising, and we have no arrangement with any data broker.
For trend collection we read public pages from Google Trends, the YouTube API and Reddit RSS. Nothing about you is sent in those requests.
5. Legal basis and your rights
If you are in the EU or UK: we process this data to perform the contract you entered when you created an account, and, for the failure warnings, on your consent when you give us an email.
You may ask us to:
- show you everything we hold about your wallet;
- correct anything wrong;
- delete the account and everything attached to it;
- export your data in a machine readable form.
Sign a message with the wallet in question and write to the address on the account page. We answer within 30 days. We ask for the signature and nothing else: proving control of the wallet is the only identity check that means anything here, and asking for a document would collect exactly the data this policy is built to avoid.
6. Security
Traffic is encrypted in transit. Sessions are signed tokens with an expiry. Your files are served only to the account that generated them, never from a guessable public path.
No one can be certain of security, so the useful statement is what a breach could expose: wallet addresses, whatever you typed into projects and briefs, and any file less than seven days old. There is no password to steal, no card, and no identity document.
7. Cookies
None. Your session token lives in your browser's local storage and is sent only to us. Nothing tracks you, which is why this site has no cookie banner: there is nothing to consent to.
8. Children
Viralux is not for anyone under 18. We do not knowingly hold data about minors, and we will delete an account we learn belongs to one.
9. Changes
Changes appear on this page with a new date. If a change means we start collecting something we do not collect today, we will say so before it takes effect, not after.
See also the Terms of Service.