Privacy Policy

Last updated: August 21, 2026

This policy explains how personal data is processed in the Find Viral App mobile application and on findviralapp.com. We do not run ads or sell personal data, and you can start using the app with a guest account without providing your name or e-mail address.

1. Controller and scope

The operator of Find Viral App, Ömer Doğan, determines why and how personal data is processed through the app and website and is the data controller for that processing.

Data controller: Ömer Doğan. Postal address: Erenler Mah. Cemre Sok. No: 23/7, İzmit / Kocaeli, Türkiye. You can also send privacy requests to contact@findviralapp.com.

This notice covers features accessible in the version submitted to the store. The community feature is disabled. YouTube channel analysis and reference-channel analysis are accessible, so their data flows are described separately below.

2. Data we process and how we collect it

  • Account and authentication data: On first launch, Supabase creates a guest account with a random user ID. If you choose to link an e-mail address, we process that address and authentication records. We do not ask for a name or phone number in the app.
  • Usage and preference data: We process the idea viewed, a session identifier, likes or dislikes, build intentions, the free-use count, language preference, and the time of those actions. Idea-level interaction totals are shown only in anonymous or aggregate form.
  • Your connected YouTube channel: If you choose to connect your own channel, we process the Google OAuth authorization, channel ID and title, public video information, YouTube Analytics metrics you authorize, the analysis fingerprint, and the resulting report and ideas. We do not receive your Google password.
  • Reference-channel analysis: A YouTube channel URL or handle you add is linked to your account. Through YouTube API Services, we retrieve the channel ID, title, thumbnail, and public subscriber, video, view, like, comment, publication-date, and duration information. We use this data to produce reports and video ideas. We do not access a reference channel’s private Analytics data, traffic sources, audience demographics, or account.
  • YouTube policy acceptance record: When you choose to continue to YouTube features, the accepted policy version, interface language, legal-document links shown, and acceptance time are linked to your account.
  • AI-assisted reports and ideas: The structured analysis derived from your channel, or the analysis prepared from public reference-channel data, is sent to the OpenAI API to generate the report and video ideas. We do not send Google access tokens, your Google password, your e-mail address, your Supabase user ID, or raw YouTube API responses to OpenAI.
  • Purchase and entitlement data: We process the store platform, product and transaction identifiers, purchase and expiry time, verification outcome, and Pro access state. We do not receive payment-card or bank-account details.
  • Notification data: If you enable rare-idea alerts, we process an Expo push token, device platform, and notification preference. The daily-idea reminder is scheduled locally on your device.
  • Website contact data: If you use the contact form, we process the name, e-mail, message, form language, and submission time you provide.
  • Technical and security data: Supabase, Vercel, Expo, and store services may process limited network logs such as IP address, request time, operating system, app or browser version, and similar metadata to deliver and protect the service and investigate errors.
  • On-device data: Session information, language, free-use history, and the local-notification preference are stored in the app sandbox. Some of this data is synchronized with the server to keep features available across devices.

3. Purposes and legal bases

  • We process data to create an account, operate the idea feed and free-use limit, synchronize preferences, verify Pro access, and provide support. This processing is necessary to enter into or perform our contract with you (KVKK Article 5(2)(c); GDPR Article 6(1)(b)).
  • We process your channel choice, the relevant YouTube API data, and the resulting analysis to provide your own-channel analysis and the comparison or launch plan based on reference channels you select.
  • We use Google user data and its derivatives only to provide or improve the channel analysis, reports, and idea-generation features that are visible in the app. Find Viral App’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not use this data for advertising, credit decisions, data sales, or general-purpose model training.
  • We rely on legitimate interests that do not override your rights to protect the service, prevent abuse and fraudulent purchase claims, measure limited aggregate use, and establish or defend legal rights (KVKK Article 5(2)(f); GDPR Article 6(1)(f)).
  • Where records must be retained or disclosed by law, we may rely on compliance with a legal obligation and the establishment, exercise, or protection of a right (KVKK Article 5(2)(ç) and (e); GDPR Article 6(1)(c) and (f)).
  • Remote notifications are enabled only with device permission and your choice in the app. Where processing relies on consent, you can withdraw it in Settings or the operating-system settings without affecting earlier lawful processing (KVKK Article 5(1); GDPR Article 6(1)(a)).
  • We process contact-form data to respond to your request, provide support, and handle possible disputes on the basis of pre-contract steps and legitimate interests.
  • We do not make solely automated decisions or perform profiling that produces legal or similarly significant effects about you.

4. Recipients, service providers, and international transfers

Some providers operate outside Türkiye and your country, so necessary personal data may be transferred internationally. Where required, we use adequacy decisions, data-processing agreements, standard contractual clauses, or other appropriate safeguards under Article 9 KVKK and Chapter V GDPR. You may request information about the applicable safeguard at contact@findviralapp.com.

  • Supabase: Guest and e-mail authentication, the PostgreSQL database, and server functions. The project is hosted in the Singapore region.
  • Expo together with Apple Push Notification Service or Firebase Cloud Messaging: Delivery of the push token and notification content only when you enable remote notifications.
  • Apple App Store or Google Play: Purchases, subscriptions, refunds, and transaction verification. A store may act as a separate controller under its own privacy policy.
  • Google and YouTube API Services: Authorization and retrieval of channel data you permit when you connect your own channel, and retrieval of public information for reference channels you select.
  • OpenAI API: Generation of the user-visible report and video ideas from the structured channel summary and reference-channel analysis. Data sent to the OpenAI API is not used to train models by default, and our requests are additionally configured with store=false.
  • Vercel: Website hosting and security-related request logs.
  • E-mail providers, competent public authorities, courts, and professional advisers: Only when necessary to answer a request, comply with law, or protect a legal right.

5. Retention

  • Account, e-mail, usage, preference, YouTube policy acceptance, and purchase-verification records are kept while the account exists and are removed from active systems when you delete the account.
  • Encrypted authorization tokens for your connected YouTube channel are kept while the connection remains active. YouTube API channel and video data, the analysis summary, its report, and evidence-based ideas are refreshed or deleted within 30 days. When a revoked Google grant is detected on the next token refresh or YouTube API attempt, the connection and derived channel data are deleted sooner.
  • Your reference-channel selection is kept until you remove the channel from the list or delete your account. Public YouTube channel counters retrieved without authorization are refreshed or cleared within 30 days; public video records captured for an analysis, its report, and the ideas based on that report are retained for no more than 30 days.
  • Because our OpenAI Responses API requests use store=false, Responses API application state is not retained. OpenAI may keep limited abuse-monitoring logs for up to 30 days by default; longer exceptions may apply for security or legal obligations.
  • When you disable rare-idea alerts, the remote push token is no longer used for delivery and a server deletion request is made; the record is removed when that request succeeds, the token becomes invalid, or you delete the account. The local reminder is cancelled when the account is deleted.
  • Contact-form submissions and support correspondence are kept only as long as necessary to resolve the request and protect rights in a possible dispute, then deleted or anonymized.
  • Security and transaction logs are retained for a limited period necessary to investigate incidents and meet applicable legal obligations.
  • Deleted data may remain in access-restricted provider backups until the ordinary backup cycle ends and is not used for another purpose during that time. Anonymous or aggregate idea statistics that can no longer be linked to you may be retained.

6. Choices and account deletion

You can delete your account in the app through Settings → Account → Delete my account. This removes the guest or e-mail account, linked e-mail, profile and preferences, idea interactions and view records, free-use history, purchase-verification records, push tokens, your YouTube connection, reference-channel list, and related analyses from active systems. The app then creates a new, empty guest account.

Deleting the account does not cancel an App Store or Google Play subscription. You must cancel the subscription separately in your store account settings.

You can disconnect your own YouTube channel in the app and revoke the Google permission from Google security settings. You can remove reference channels individually from the competitor-analysis screen.

You can disable notifications in the app or operating-system settings. You can also send a privacy request to contact@findviralapp.com; we may need to verify your relationship to the account before acting on the request.

7. Your rights and how to exercise them

Under Article 11 KVKK, you may ask whether your personal data is processed; request information about the data, purposes, and recipients; have inaccurate data corrected; request deletion or destruction where the conditions apply and notification of that action to recipients; object to an adverse result based only on automated analysis; and seek compensation for unlawful processing.

Where the GDPR applies, you may also have rights of access, rectification, erasure, restriction, data portability, objection to legitimate-interest processing, and withdrawal of consent for future processing.

Send your request to contact@findviralapp.com, preferably from the e-mail linked to the account. KVKK requests are answered as soon as possible and no later than 30 days, depending on the request. After contacting the controller first, you may complain to the Turkish Personal Data Protection Authority or, where the GDPR applies, the competent supervisory authority in your location.

8. Security

We use measures such as HTTPS in transit, row-level database security, server-side authorization checks, server verification of store transactions, and separation of administrative keys from the client. No system is completely risk-free, so we limit access and stored data to what is necessary.

9. Data we do not collect or use

  • We do not use advertising identifiers, include third-party advertising SDKs, or track you across other companies’ apps or websites.
  • We do not access your contacts, photos, location, or microphone.
  • We do not sell, rent, or provide personal data to data brokers.

10. Children

The service is not directed to children under 13, and we do not knowingly collect personal data from them. If your country sets a higher age for consenting to digital services, do not provide optional data or consent below that age without a parent or legal guardian. Contact us if you believe we processed a child’s data by mistake.

11. Changes

We update this page and its date when data flows, providers, or legal requirements change. Where appropriate, we will also announce material changes in the app and ask for any choice that must be renewed.

12. Contact

For privacy questions, rights requests, and deletion support: contact@findviralapp.com