Legal
Privacy Policy
Last updated: 6 August 2026
This policy explains what information ShadowViral AI (“we”, “the service”) collects when you use shadowviral.com, why we collect it, who we share it with, how it is transmitted, and the safeguards we apply. It applies to the website, the analysis and script-generation features, and the billing experience.
Data controller. ShadowViral AI is operated by a registered sole trader (obrt) established in the Republic of Croatia, European Union. As the controller of your personal data we process it under Regulation (EU) 2016/679 (GDPR) and the Croatian Act on the Implementation of the GDPR. You can reach us at support@shadowviral.com. We have not appointed a data protection officer, as we are not required to.
1. Information we collect
We collect only what the service needs to operate, bill correctly, and stop abuse.
- Account information. Email address, password (stored only as a salted hash by our authentication provider), and display name.
- Billing profile. Full name, postal address, and contact details you supply at registration or checkout. Addresses may be standardised into a normalised form for matching.
- Payment information. Card details are entered directly into our payment processor and never reach our servers. We store the processor’s customer and subscription identifiers, plan, status, renewal dates, invoice history, and a non-reversible fingerprint of the payment instrument.
- Anti-abuse signals. Hashed combinations of name, address, contact details and payment fingerprint, plus a one-time trial-eligibility flag, used to detect duplicate accounts and repeat free trials.
- Content and usage data. The categories and videos you open, analyses you request, scripts you generate, saved items, and job records for asynchronous AI tasks.
- Communication preferences. Newsletter consent and per-type notification toggles for invoices, renewals, failed payments and trial reminders.
- Cancellation feedback. Exit-poll answers, which you may skip.
- Technical and security logs. IP address, browser user agent, timestamps, bot-protection challenge results, administrative access records, and payment-webhook processing logs.
We do not knowingly collect information from children under 16, and we do not collect special-category data (health, biometrics, political or religious views).
2. How we use the information
- Create and authenticate your account and keep you signed in.
- Determine your access tier (guest, registered, trial, subscriber) and enforce entitlements.
- Run the analyses and script generation you request, and return the results.
- Take payment, manage renewals and cancellations, and issue invoices and receipts.
- Send service messages you have not switched off: invoices, renewal confirmations, failed-payment notices, trial reminders, password resets and sign-in links.
- Send the newsletter, only where you gave consent, until you withdraw it.
- Prevent fraud and abuse, including duplicate registrations and repeated free trials.
- Debug, monitor reliability, and keep the service secure.
- Improve the product using aggregated, non-identifying usage patterns.
Where the GDPR or similar law applies, we rely on: performance of a contract (account, access, billing); legitimate interests (security, fraud prevention, service improvement); consent (newsletter, optional notifications); and legal obligation (tax and accounting records).
3. Who we disclose information to
We do not sell your personal information and we do not share it with advertising networks or data brokers. We disclose it only to the following categories of recipient, each acting as our processor or as an independent controller for the part they handle:
- Cloud and database hosting. Stores your account, billing profile, saved analyses and scripts, and the application logs.
- Payment processor. Receives your name, email, billing address and card details to take payment, manage subscriptions, and issue invoices. It is an independent controller for payment and anti-fraud purposes.
- AI model provider. Receives the video metadata and prompt text needed to produce an analysis or script. We do not send your name, address, contact details or payment data to the model.
- Transactional email provider. Receives your email address and message content to deliver account and billing emails.
- Address validation and bot protection. Receive the address you enter and a challenge token plus IP address respectively.
- Professional advisers and authorities. Only where we are legally required, or to establish or defend legal claims.
- A successor entity in a merger, acquisition or asset sale, subject to this policy.
4. How disclosure happens
All disclosures are machine-to-machine over encrypted connections. Specifically:
- Data travels over HTTPS/TLS 1.2 or higher; we do not transmit personal data by unencrypted email, file exports to third parties, or physical media.
- Card details are collected inside the payment processor’s hosted checkout component, so they pass from your browser to the processor without traversing our servers.
- Payment status flows back to us through signed webhooks whose signatures we verify before the payload is processed; verification failures are rejected and logged.
- Requests to the AI provider are made server-side over authenticated API calls containing only the prompt payload.
- Administrative exports (for example cancellation analytics) are generated on demand for signed-in administrators and are recorded in an append-only audit log.
- Some providers process data outside your country. Where required, transfers rely on Standard Contractual Clauses or an equivalent safeguard.
5. How we safeguard the information
- Encryption in transit (TLS) and at rest for the database and backups.
- Row-level security on every table, so a signed-in user’s queries can reach only their own rows; sensitive tables are writable only by trusted backend processes.
- Privileged database functions are not executable by ordinary signed-in users, and administrative capability is granted through a separate roles table rather than a flag on your profile.
- Passwords are hashed by the authentication provider; we never see them.
- Card numbers are never stored by us; anti-abuse matching uses non-reversible fingerprints rather than raw card data.
- Secrets and API keys are held in an encrypted secret store, read only by server-side code; scheduled maintenance endpoints require a private secret that is never shipped to the browser.
- Bot protection on registration, and duplicate-identity checks to limit automated abuse.
- Append-only audit logging of administrative access and of webhook signature failures, with alerting and a dead-letter queue so billing state cannot silently drift.
- Least-privilege access for staff, and automated policy checks before deployment.
No system is perfectly secure. If a breach affects your personal data and poses a risk to you, we will notify you and any competent authority as required by law.
6. How long we keep it
- Account, profile and saved content: while your account is open.
- Invoices and payment records: as long as tax and accounting law requires, typically seven years.
- Anti-abuse fingerprints and the trial-used flag: retained after account deletion, because deleting them would defeat their purpose. They are hashed and cannot be reversed into your card or address.
- Security and audit logs: up to 24 months.
- Cancellation survey answers: retained in aggregate for product analysis.
7. Your choices and rights
- Access, correction, deletion. Edit your billing profile on the billing page, or ask us to export or delete your data.
- Marketing. Withdraw newsletter consent at any time; unsubscribing does not stop essential billing notices.
- Notification control. Turn invoice, renewal, failed-payment and trial-reminder emails on or off individually.
- Portability and objection. Where the GDPR or UK GDPR applies, you may request portability, restriction, or object to processing based on legitimate interests.
- Complaint. You may complain to the Croatian Personal Data Protection Agency (AZOP), Selska cesta 136, 10000 Zagreb, Croatia — azop.hr, or to the supervisory authority in your own EU member state.
To exercise any of these, email support@shadowviral.com. We respond within 30 days.
9. Changes to this policy
We will update the date at the top when this policy changes, and will notify account holders by email before any change that materially reduces your privacy protections.
10. Contact
Questions about this policy or your data: support@shadowviral.com.
See also our Terms of Service.