In short: we collect what we need to run your account and your Flows. We don't sell personal data, and we don't use your audience's messages to train models for anyone else. You can export or delete your data whenever you want.
1. Who we are
Virooly ("Virooly", "we", "us") is a social media automation platform for businesses and creators.
For privacy questions, contact us at privacy@virooly.com.
2. Our two roles
Which role we play depends on whose data it is.
We are the controller
For data about you as a Virooly customer — your account, your billing details, how you use the product — we decide why and how it is processed, so we are the data controller.
We are the processor
For data about the people who interact with your connected accounts — their comments, messages, profile handles and the answers they give your Flows — you decide why and how it is processed. You are the controller and we act as your processor, handling it on your instructions.
That means you are responsible for having a lawful basis to message those people, for telling them how you use their data, and for honouring their requests. We will help you do so.
3. What we collect
Account data
- Name, email address and password (stored only as a salted hash).
- Business name, role and country, where you provide them.
- Communication preferences and support correspondence.
Billing data
- Plan, billing cycle, invoices and payment status.
- Billing address and tax identifiers where required.
- Card details are handled by our payment provider — we never see or store full card numbers.
Connected account data
- Access tokens issued by the platform when you authorise a connection.
- Your account's public profile details, such as handle, name and profile picture.
- Posts, comments, mentions, story replies and messages needed to evaluate your Flow triggers.
End user interaction data
- The handle and public profile information of people who interact with you.
- The content of the comments and messages that trigger or move through your Flows.
- Answers given to qualification questions, and any tags or scores your Flow applies.
Usage and technical data
- Flow configurations, run history, delivery outcomes and error logs.
- IP address, browser and device type, and pages viewed in the dashboard.
- Diagnostic logs used to detect abuse and fix faults.
4. How we use it
- To run the Service — evaluating triggers, executing Flows, sending the replies and messages you configured.
- To manage your account — authentication, billing, and support.
- To show you analytics — how your Flows performed and which ones produced conversations.
- To keep the platform safe — detecting abuse, spam, fraud and security incidents.
- To improve the product — using aggregated and de-identified usage patterns.
- To communicate — service notices, security alerts and, where you have opted in, product updates.
- To meet legal obligations — accounting, tax and lawful requests.
We do not sell personal data, and we do not share it for cross-context behavioural advertising. We do not use your End Users' message content to train machine learning models for other customers or third parties.
5. Legal bases (UK/EU)
Where the UK GDPR or EU GDPR applies, we rely on:
- Contract — to provide the Service you signed up for.
- Legitimate interests — to secure the platform, prevent abuse, and improve the product, balanced against your rights.
- Consent — for optional analytics cookies and marketing email, which you can withdraw at any time.
- Legal obligation — for tax, accounting and compliance duties.
6. Social platform data
When you connect an account, the platform grants Virooly an access token limited to the permissions you approve. We use it only to deliver the features you have configured.
- We request the narrowest set of permissions the features need.
- We store tokens encrypted, and we never share them with other customers.
- You can disconnect an account in Virooly at any time, or revoke access from the platform's own settings. We delete the token when access is revoked.
- Data obtained through a platform is handled in line with that platform's developer terms as well as this policy.
Virooly is not affiliated with, endorsed by, or sponsored by Instagram or Meta Platforms, Inc.
7. Who we share data with
We share personal data only with parties that help us run the Service:
- Cloud hosting and storage — to operate the platform and store your data.
- Payment processing — to take payments and issue invoices.
- Email delivery — for transactional and, where opted in, marketing email.
- Error monitoring and analytics — to diagnose faults and understand product usage.
- Social platforms — to send the messages and replies your Flows produce.
Each provider is bound by a contract limiting them to processing data on our instructions. A current list of our sub-processors is available on request from privacy@virooly.com.
We may also disclose data where legally required, to enforce our Terms, or as part of a merger or acquisition — in which case we will notify you before your data becomes subject to a different policy.
8. Cookies
We keep cookie use deliberately minimal.
Strictly necessary
Used to keep you signed in, remember your session, and protect against cross-site request forgery. These cannot be switched off without breaking the product.
Preferences
Used to remember choices such as your dashboard layout.
Analytics
Used, where you consent, to understand which features get used so we can improve them. You can decline these without losing functionality.
This marketing website sets no tracking cookies and loads no third-party scripts, fonts or trackers. You can also control cookies through your browser settings.
9. International transfers
We may process data in countries other than your own, including where our hosting and service providers operate. Where data leaves the UK or EEA, we rely on an adequacy decision or on Standard Contractual Clauses together with appropriate technical safeguards. You can request details of the safeguards used.
10. How long we keep it
- Account data — while your account is open, then up to 30 days after closure.
- Flow and interaction data — for the retention window on your plan, or until you delete it.
- Billing records — for as long as tax and accounting law requires, typically six to seven years.
- Security and diagnostic logs — typically 90 days.
- Backups — deleted data may persist in encrypted backups for a short period before being overwritten.
When a retention period ends, we delete the data or irreversibly anonymise it.
11. How we protect it
- Encryption in transit using TLS, and encryption at rest for stored data.
- Access tokens and secrets stored encrypted, with access limited to the systems that need them.
- Role-based access control and least-privilege access for our staff.
- Passwords stored only as salted hashes — never in plain text.
- Logging, monitoring and alerting for unusual activity.
- Regular dependency patching and review of our infrastructure.
No system is perfectly secure. If a breach affects your personal data and poses a risk to your rights, we will notify you and the relevant regulator as the law requires.
12. Your rights
Depending on where you live, you may have the right to:
- Access a copy of the personal data we hold about you.
- Rectify data that is inaccurate or incomplete.
- Erase your data where we no longer need it.
- Restrict or object to certain processing, including direct marketing.
- Port your data to another provider in a machine-readable format.
- Withdraw consent at any time, without affecting earlier processing.
- Not be discriminated against for exercising any of these rights.
To exercise a right, email privacy@virooly.com. We respond within one month, and will tell you if we need longer. We may need to verify your identity first.
If you are in the UK or EEA and are unhappy with our response, you may complain to your local supervisory authority. In the UK that is the Information Commissioner's Office.
13. If you received a message from a Virooly customer
If you commented on or messaged a business that uses Virooly and received an automated reply, that business — not Virooly — decides what data is collected and why. They are the data controller.
- Contact that business directly to access, correct or delete your data.
- Ask them to stop messaging you, and they are required to honour it.
- You can also block or restrict the account on the platform itself.
If you cannot reach them, write to privacy@virooly.com and we will pass your request to the relevant customer and support them in responding.
14. Children
Virooly is not directed at children and is not intended for anyone under 18. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, contact us and we will delete it.
15. Changes to this policy
We may update this policy as the product, our providers or the law change. We will update the date at the top of this page, and for material changes we will notify you by email or in-product notice before they take effect.
16. Contact us
We would rather hear from you than have you wonder.
- Privacy: privacy@virooly.com
- Security: security@virooly.com
- General: hello@virooly.com