Virali

Privacy Policy

Last updated: August 25, 2026

Virali ("Virali," "we," "our," or "us") provides creator relationship management, campaign operations, onboarding, outreach, messaging, and related business tools. This Privacy Policy explains how we collect, use, disclose, retain, and protect information when you use Virali's websites, applications, integrations, and related services (collectively, the "Services").

By using the Services, you acknowledge the practices described in this Privacy Policy. If you use Virali on behalf of a company or other organization, that organization may control the information placed in its Virali workspace and may have its own privacy obligations to creators, employees, contractors, and other individuals.

1. Information We Collect

Account and workspace information

We may collect names, email addresses, authentication information, profile details, workspace membership, roles, permissions, preferences, and billing or subscription status.

Creator, campaign, and business information

Users may enter or upload creator and contact information, social-media handles, campaign details, rates, contracts, payment and payout information, onboarding responses, content schedules, performance information, notes, files, and related business records. Where a workspace uses credential-collection features, certain credentials or account-access information may be submitted and stored using restricted-access secrets-management controls.

Google account and Gmail information

When you connect a Google account, we receive basic account and connection information from Google and OAuth credentials that allow Virali to perform the functions you authorize. Virali may access Gmail message content and associated metadata—such as sender and recipient addresses, subject lines, timestamps, message and thread identifiers, and delivery or reply status—to identify, sync, display, and manage replies connected to outreach conversations handled through Virali.

Virali may also process outbound messages that users compose, approve, schedule, or send through the Services. We do not intentionally use unrelated mailbox content for purposes outside the user-facing Gmail and outreach features described in this Privacy Policy.

Communications and support

We may collect messages, attachments, call notes, support requests, and other information you provide when communicating with us or using collaboration and messaging features.

Usage, device, and security information

We may collect browser and device information, IP address, approximate location derived from IP address, log-in and authentication events, feature usage, diagnostic data, audit logs, error reports, and security events.

2. How We Use Information

We use information to:

  • Create, authenticate, secure, and administer accounts and workspaces.
  • Provide creator CRM, campaign, onboarding, contracting, payout, reporting, and collaboration features.
  • Connect Google accounts and provide Gmail sending, reply synchronization, shared inbox, thread tracking, and related outreach features.
  • Generate user-requested message drafts, summaries, classifications, recommendations, and workflow assistance.
  • Operate automations that users configure or approve.
  • Provide support, troubleshoot problems, and communicate about the Services.
  • Monitor performance, prevent abuse, investigate security incidents, and protect users and the Services.
  • Comply with legal obligations and enforce our agreements.

3. Google Workspace and Gmail Data

Virali's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

We use Google Workspace and Gmail data only to provide or improve visible, user-facing features, including:

  • Sending messages that a user composes, approves, schedules, or authorizes.
  • Detecting and synchronizing replies to Virali-managed outreach conversations.
  • Displaying relevant conversations in Virali's inbox and CRM.
  • Maintaining thread status, assignments, reminders, and reply-needed indicators.
  • Producing a draft, summary, or classification when a user invokes an AI-assisted feature.

Authorized members of the same Virali workspace may view synced outreach conversations when their assigned permissions allow it. This shared-workspace access is a core part of the Services. Workspace administrators are responsible for granting appropriate access and informing their users about internal access.

We do not sell Google user data. We do not use Google user data for advertising, retargeting, credit-worthiness, lending, or data-broker purposes. We do not use Google Workspace data to train, fine-tune, or improve generalized or non-personalized artificial-intelligence or machine-learning models.

We do not allow employees, contractors, or other humans to access Google user data except when access is authorized by the user or workspace, is necessary to provide requested support, is required to investigate security or abuse, is required by law, or involves appropriately aggregated information used for internal operations.

4. AI-Assisted Features

Virali may provide AI-assisted drafting, summarization, classification, or workflow features. When a user invokes one of these features, Virali may send the minimum relevant content—such as a portion of an outreach conversation and related instructions—to an AI service provider solely to generate the requested output.

We do not authorize AI service providers to use Google Workspace data to train their general-purpose models. AI-generated output may be incomplete or inaccurate, and users should review it before sending or relying on it.

5. How We Share Information

We may share information only as described below:

  • Within your workspace: with authorized workspace members based on roles, assignments, and permissions.
  • Service providers: with vendors that provide hosting, databases, authentication, security, monitoring, communications, file storage, analytics, payment processing, and AI processing on our behalf.
  • At your direction: when you connect an integration, send a message, export information, invite a user, or otherwise direct us to disclose information.
  • Security and legal reasons: when reasonably necessary to protect the Services, users, or others; investigate abuse or fraud; enforce agreements; or comply with applicable law or legal process.
  • Business transactions:in connection with a merger, acquisition, financing, reorganization, or sale of assets, subject to applicable legal and contractual requirements. Google user data will be handled in accordance with Google's applicable consent requirements.

We do not sell personal information or Google user data, and we do not sell or share Customer Personal Information for cross-context behavioral advertising. For customer workspace data processed on customer instructions, Virali generally acts as a service provider or contractor. Virali acts as a business or controller for its own account administration, billing, website, marketing, sales, security, fraud-prevention, and legal-compliance activities.

Virali does not use third-party advertising cookies or permit third parties to track users across unaffiliated websites for targeted advertising through the Services. Service providers may process limited device, usage, or diagnostic information to operate features requested by users, subject to their role as a service provider to Virali.

Where legally applicable, we honor browser-based Global Privacy Control signals as an opt-out for the browser or device sending the signal. We do not use a GPC signal as an authenticated request to delete a workspace or account.

6. Data Security

We use administrative, technical, and organizational safeguards designed to protect information against unauthorized access, disclosure, alteration, loss, or misuse. These measures may include encrypted connections, access controls, role-based permissions, multifactor authentication for privileged access, security logging, dependency and vulnerability management, secrets-management controls, and restricted production access.

No system is completely secure. Users are responsible for protecting their account credentials, configuring workspace permissions appropriately, and promptly notifying us of suspected unauthorized access.

7. Data Retention and Deletion

Active customer workspace content is retained while the workspace is active. Normal workspace and account deletion uses a 30-day recovery period followed by permanent deletion from active systems. A verified privacy erasure request may bypass that recovery period. Protected backups use a maximum rolling 30-day schedule and are not available for ordinary product access.

Customer-uploaded creator, contact, content, message, and Gmail data follows the workspace lifecycle. Independently collected creator leads and Virali sales leads are ordinarily deleted 12 months after the relevant last meaningful use, verification, or substantive interaction. Support records are retained two years after closure, audit logs two years, and authentication/security logs one year. Security-incident records are retained seven years after closure and fraud-investigation records four years after closure.

Application logs and provider logs are retained for 90 days after creation. Provider enforcement depends on the provider's supported settings and deletion mechanisms. These categories are distinct from the longer security, audit, incident, and fraud records described above.

Billing and tax records are retained seven years after the applicable fiscal year; contracts and order forms seven years after termination; recurring-subscription consent records four years after subscription termination; privacy or marketing consent evidence four years after withdrawal or last reliance; and privacy-request and minimized deletion-receipt records 24 months after completion. Legal or security holds override deletion only for records within the documented hold scope.

Users and workspace administrators may request deletion of personal information or Google-derived data by contacting us at support@tryvirali.com. We may retain limited information when required for legal, security, fraud prevention, accounting, or compliance purposes. Residual copies may remain in protected backups for a limited period before aging out through the 30-day backup cycle.

8. Your Choices and Rights

Depending on your location and relationship with Virali, you may be able to:

  • Access, correct, export, or delete certain information.
  • Manage workspace roles, assignments, and permissions.
  • Disconnect a Google account through Virali's integration settings.
  • Revoke Virali's Google access through your Google Account permissions.
  • Object to or restrict certain processing where applicable.
  • Withdraw consent where processing is based on consent.

Some information is controlled by the organization that owns your Virali workspace. In that situation, please contact the workspace administrator first. You may also contact us at support@tryvirali.com.

To submit a privacy request, email support@tryvirali.comwith the subject line "Privacy Request" and describe the request and the account or workspace involved. We will acknowledge the request, take reasonable steps to verify the requester's identity and authority, route workspace-controlled requests to the appropriate workspace owner when necessary, and ordinarily respond within one calendar month after receipt. Where applicable law permits an extension, we may extend by no more than two additional calendar months and will provide the reason and notice by the original deadline. A verified formal erasure request targets the approved scope in active systems within 30 days after verification and may bypass the normal workspace recovery period. Provider and protected-backup copies follow their documented deletion and rolling-expiration process. Do not send passwords, authentication codes, or other secrets with a request.

9. International Processing

Virali is operated from the United States. Information may be processed in the United States and other countries where we or our service providers operate. Those countries may have data-protection laws that differ from the laws where you live.

Where a transfer mechanism is required, Virali uses an applicable adequacy decision, a verified Data Privacy Framework certification where available and applicable, the European Commission Standard Contractual Clauses, the UK Addendum, or the UK International Data Transfer Agreement, as appropriate. Virali does not promise data residency unless an executed agreement expressly provides it.

10. California, EEA, and United Kingdom Rights

California residents may have rights to know, access, correct, delete, and obtain information about disclosures, and to opt out of sale or sharing where applicable. Virali does not discriminate for exercising applicable rights and retains request records for 24 months. EEA and UK individuals may have rights to access, correct, erase, restrict, port, object, withdraw consent, and complain to a supervisory authority, subject to applicable limits.

Virali has designated a Privacy Lead. Virali does not claim to have appointed a statutory data protection officer, EU representative, or UK representative unless separately announced. Submit requests to support@tryvirali.com with the subject “Privacy Request.”

11. Children's Privacy

Virali is a business service and is not directed to children under 13. We do not knowingly collect personal information directly from children under 13. If you believe a child has provided personal information to us, contact us so we can take appropriate action.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will post the updated version and revise the "Last updated" date. If changes materially affect how we use Google user data or other personal information, we will provide additional notice and seek consent when required.

13. Contact Us

For privacy questions, requests, or concerns, contact:

Virali
Email: support@tryvirali.com
Website: app.tryvirali.com