Legal

Privacy Policy

Last updated: August 27, 2026

This Privacy Policy explains how VioPost (“VioPost”, “we”, “us”, or “our”), operated by emtsco, collects, uses, discloses, and protects personal information when you use VioPost and the website at viopost.com (together, the “Service”). It applies to visitors, account holders, and anyone whose information we process in connection with the Service.

We aim to comply with applicable privacy laws, including the EU and UK General Data Protection Regulation (“GDPR”), the California Consumer Privacy Act as amended by the California Privacy Rights Act (“CCPA/CPRA”), and other U.S. state privacy laws. Defined terms such as “personal information” and “personal data” are used interchangeably to mean information that identifies or relates to an identifiable individual.

1. Who we are

VioPost is an AI-powered studio that turns an article URL or text you provide into branded social media assets (captions, images, carousels, and narrated videos), in the language you choose, and publishes them to the social accounts you connect. For personal data we process about residents of the European Economic Area (“EEA”) and the United Kingdom, the data controller is emtsco, located in Maryland, USA. You can reach us at admin@emtsco.com.

2. Information we collect

We collect the following categories of personal information:

Information you provide to us

  • Account information. When you sign up, our authentication provider (Clerk) collects your name, email address, and credentials or third-party sign-in identifiers used to create and secure your account.
  • Brand and company settings. Information you enter to brand your output, such as company name, website, contact email, logo, brand colors and typography, and a local save path. If you ask us to build your brand kit automatically, we fetch the website address you give us and read its public pages to detect your colors, fonts, logo, and tagline. You may also upload your own font files, which we store so we can render them into your assets.
  • Source content. The article URLs or text you submit for generation, any instructions you give the in-app assistant (including short voice recordings you dictate, which we transcribe to text), the language you choose for a post, and the assets the Service produces for you.
  • Uploaded media. Files you upload to the Service — images or videos you upload as your own posts, and background images you upload to create custom templates — which we store on our servers so we can display them, render them into your assets, and schedule or publish them at your direction.
  • Communications. Information you provide when you contact support or correspond with us.
  • Newsletter sign-up. If you subscribe to our mailing list, we collect your email address (and confirm it by double opt-in where applicable) to send you the updates you asked for. You can unsubscribe at any time.
  • Payment and billing information. When you subscribe to a paid plan or add funds to your wallet, our payment processor (Stripe) collects and processes your payment card or account details on our behalf. We do not receive or store full payment card numbers; we retain billing records such as your wallet balance, transaction and usage history, subscription tier and status, and the amounts charged.
  • Connected social accounts. When you connect a third-party platform — LinkedIn, Facebook and Instagram (through Meta, or Instagram on its own using an Instagram Professional account), X (Twitter), Google (YouTube and Business Profile), TikTok, Pinterest, Reddit, Bluesky, Threads, Telegram, or Snapchat — we store the access (and, where provided, refresh) tokens it issues, encrypted at rest, together with the account, profile, Page, channel, or business-account identifiers needed to publish on your behalf. For Bluesky you supply an app password, which we exchange for a session token and do not store; for Telegram you supply a bot token, which we store encrypted. Disconnecting the platform deletes these stored credentials.
  • Saved and scheduled content. Posts you save to your library and posts you schedule are stored on our servers — including the post data and any rendered video — so you can revisit, edit, publish, or schedule them.
  • Studio design edits. If you edit a saved single-image post in Studio, our visual editor, we store the design project — the element positions, sizes, rotation, typography, colors, and text you change, and any text, image, or shape elements you add — linked to that post.
  • Team and organization workspaces. If you create or join a shared organization, resources such as your content library, connected accounts, brand settings, prepaid wallet, and — where enabled — post approvals are shared with the other members of that organization, and we record which member performed an action for audit and approval purposes.

Information collected automatically

  • Usage and device data. Log data such as IP address, browser type, pages viewed, and timestamps, used to operate and secure the Service.
  • Cookies and local storage. We and our providers use cookies and browser local storage (for example, to keep you signed in and to remember your preferences). See “Cookies and local storage” below.

When you submit a URL, we fetch and process the content of that public web page to generate your assets. Please do not submit content you are not authorized to use, and avoid including sensitive personal information in your inputs.

3. How we use information

We use personal information to:

  • Provide, operate, and maintain the Service and generate the assets you request;
  • Create and authenticate your account and keep it secure;
  • Process payments, manage your subscription and prepaid wallet, and prevent payment fraud;
  • Personalize output with your brand settings;
  • Respond to your requests and provide customer support;
  • Monitor, debug, and improve the Service and develop new features;
  • Detect, prevent, and address fraud, abuse, and security incidents;
  • Send you newsletters and product updates where you have opted in, which you can unsubscribe from at any time; and
  • Comply with legal obligations and enforce our terms.

4. AI processing of your content

To generate assets, the source content and instructions you provide are sent to our third-party AI provider, Google (Gemini, Imagen, and speech-to-text and text-to-speech services), acting as our processor. This includes short voice recordings you dictate to the in-app assistant, which are transcribed to text, together with the language you ask us to write in. Your inputs and outputs are processed to return results to you. We do not use the content you submit to train our own models. Google’s processing of data submitted through its paid API is governed by its applicable terms and data-protection commitments.

6. How we share information

We do not sell your personal information. We share it only as described below:

  • Service providers (processors). Vendors who process data on our behalf under contract, including Clerk (authentication), Google (AI generation), Stripe (payment processing), Brevo (email delivery), Cloudflare R2 (object storage for generated media, uploaded images, videos, and templates), and our hosting/infrastructure providers.
  • Legal and safety. When required by law, legal process, or to protect the rights, property, or safety of VioPost, our users, or the public.
  • Business transfers. In connection with a merger, acquisition, financing, or sale of assets, subject to this Policy.
  • With your direction. When you choose to export, save, publish, or schedule content to a destination you select — for example, when you publish or schedule a post to a connected platform such as LinkedIn, Facebook, Instagram, X (Twitter), Bluesky, Threads, or Telegram — we transmit that content and any media to that platform at your direction, subject to its own terms and privacy practices. Some platforms — including Instagram, Threads, Pinterest, TikTok, and Google Business Profile — do not accept media uploaded directly and instead fetch it from a link. For those, we make the post’s image or video briefly available at an unguessable temporary public URL and delete the file once publishing completes.

7. Cookies and local storage

We use strictly necessary cookies and browser local storage to run the Service (for example, to maintain your session and store preferences). We honor opt-out preference signals, including the Global Privacy Control (“GPC”), where required by law. You can control cookies through your browser settings, though some features may not function without them.

8. Data retention

We retain personal information for as long as needed to provide the Service, maintain your account, comply with our legal obligations, resolve disputes, and enforce our agreements. When information is no longer needed, we delete or de-identify it. You may delete your data yourself at any time, or ask us to, as described under “Your privacy rights.”

Posts you create are saved to your library and are automatically deleted after a short period (currently a few days) unless you keep or schedule them. Posts you keep or schedule, and any media stored to publish them — including images or videos you upload as your own posts — are retained until you delete them or close your account. Background images you upload for a custom template are retained until you delete that template or close your account. Tokens for a connected social account are retained until you disconnect that platform. If you edit a post in Studio, our visual editor, the design project is retained together with that post and is deleted when you delete the post or close your account. Publishing or scheduling from Studio also creates a render snapshot — an immutable, point-in-time copy of the design used to produce that specific render — which is short-lived and expires automatically about 15 minutes after it is created.

Generated media and uploaded files are stored with a third-party object-storage provider (Cloudflare R2). Narrated videos are retained for a plan-specific window: videos made during the free trial are kept only for the trial, and each paid plan (Lite, Starter, Pro, and Enterprise) keeps them progressively longer, as set out on our pricing page. After the applicable window, video files may be permanently deleted. We encourage you to download any content you wish to keep before the retention period expires.

9. Data security

We implement reasonable technical and organizational measures designed to protect personal information against unauthorized access, loss, or misuse, including encryption in transit and access controls. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

10. International data transfers

We and our providers may process and store personal information in the United States and other countries that may have different data-protection laws than your jurisdiction. Where we transfer personal data out of the EEA or UK, we use appropriate safeguards such as the European Commission’s Standard Contractual Clauses (and the UK Addendum) or other lawful transfer mechanisms.

11. Your privacy rights

EEA and UK residents

Subject to applicable law, you have the right to access, correct, delete, or receive a portable copy of your personal data; to restrict or object to certain processing; and to withdraw consent. You may also lodge a complaint with your local supervisory authority.

California residents (CCPA/CPRA)

In the preceding 12 months we may have collected the following categories of personal information: identifiers (e.g., name, email, IP address), customer records, commercial information, internet or network activity, and the content you submit. We collect this information for the business purposes described above and disclose it to the service providers listed above. You have the right to:

  • Know and access the personal information we have collected about you;
  • Delete personal information, subject to legal exceptions;
  • Correct inaccurate personal information;
  • Opt out of the “sale” or “sharing” of personal information — note that we do not sell or share personal information as those terms are defined under the CCPA/CPRA;
  • Limit the use of sensitive personal information (we do not use sensitive personal information for purposes that require an opt-out); and
  • Not receive discriminatory treatment for exercising your rights.

Other U.S. state residents

Residents of states such as Virginia, Colorado, Connecticut, Utah, Texas, Oregon, and other states with comprehensive privacy laws may have similar rights to access, correct, delete, and obtain a copy of their personal data, and to opt out of targeted advertising, sale, or certain profiling. We do not sell personal data or use it for targeted advertising.

How to exercise your rights

If you have an account, you can exercise your access, portability, and deletion rights yourself — immediately and without contacting us. Open the account menu, choose Manage account, then Privacy & Data, where you can:

  • Download my data — a machine-readable JSON copy of your posts, wallet history, connected accounts (excluding the access tokens themselves), and profile. This serves both your right of access and your right to data portability.
  • Clear my data — erases your posts, wallet history, connections, brand kit, and scheduled posts while leaving your login active, so you keep the account but none of its content.
  • Delete my account — permanently closes your account and erases your data. This cannot be undone.

If you administer an organization, the same page additionally lets you download the organization’s data and erase the organization’s shared posts, wallet, connections, and settings.

For corrections, for objections to or restriction of processing, for withdrawal of consent, or for any request you cannot complete in the app — including requests made by an authorized agent, or by someone without an account — email admin@emtsco.com or use our contact page. We will verify your request and respond within the timeframe required by applicable law. You may use an authorized agent where permitted. If we deny your request, you may appeal by replying to our response.

12. Disconnecting a platform and deleting platform data

You can disconnect any social account from Connectionsin the app at any time. Disconnecting deletes the access and refresh tokens we hold for that platform, along with the account, Page, channel, board, or business-account identifiers we stored to publish on your behalf. It does not delete posts you already published — those live on the platform and are governed by its own terms — and it does not delete the posts saved in your VioPost library, which you control from the Library and the Privacy & Data page.

Facebook, Instagram, and Threads users

If you remove VioPost from your Facebook, Instagram, or Threads account, or submit a data deletion request through Meta, Meta notifies us automatically and we immediately delete the tokens and platform identifiers we hold for that account. No further action is needed on your part. You can also request this directly:

  • From the platform. In Facebook, open Settings & privacy → Settings → Apps and Websites, select VioPost, and choose Remove; in Instagram or Threads, open Settings → Website permissions → Apps and websites and remove VioPost. In Instagram you may also choose Request data deletion.
  • From VioPost. Open Connections and disconnect the account, or use Manage account → Privacy & Data to erase all of your data at once.
  • By email. Write to admin@emtsco.com and we will confirm deletion.

This page is the deletion status page referenced in our response to Meta’s data deletion callback: because we delete the stored credentials as soon as the request arrives, a deletion request is complete by the time you are directed here.

13. Children's privacy

The Service is not directed to children under 16, and we do not knowingly collect personal information from children under 16 (or under 13 where COPPA applies). If you believe a child has provided us personal information, contact us and we will delete it.

15. Changes to this Policy

We may update this Policy from time to time. When we do, we will revise the “Last updated” date above and, where required, provide additional notice. Your continued use of the Service after changes take effect constitutes acceptance of the updated Policy.

16. Contact us

If you have questions about this Policy or our privacy practices, contact us at admin@emtsco.com or emtsco, Maryland, USA. You can also reach us through our contact page.