Privacy Policy
Last updated: July 9, 2026
This Privacy Policy explains how VioPost (“VioPost”, “we”, “us”, or “our”), operated by emtsco, collects, uses, discloses, and protects personal information when you use VioPost and the website at viopost.com (together, the “Service”). It applies to visitors, account holders, and anyone whose information we process in connection with the Service.
We aim to comply with applicable privacy laws, including the EU and UK General Data Protection Regulation (“GDPR”), the California Consumer Privacy Act as amended by the California Privacy Rights Act (“CCPA/CPRA”), and other U.S. state privacy laws. Defined terms such as “personal information” and “personal data” are used interchangeably to mean information that identifies or relates to an identifiable individual.
1. Who we are
VioPost is an AI-powered studio that turns an article URL or text you provide into branded social media assets (captions, images, carousels, and narrated videos). For personal data we process about residents of the European Economic Area (“EEA”) and the United Kingdom, the data controller is emtsco, located in Maryland, USA. You can reach us at admin@emtsco.com.
2. Information we collect
We collect the following categories of personal information:
Information you provide to us
- Account information. When you sign up, our authentication provider (Clerk) collects your name, email address, and credentials or third-party sign-in identifiers used to create and secure your account.
- Brand and company settings. Information you enter to brand your output, such as company name, website, contact email, logo, and a local save path.
- Source content. The article URLs or text you submit for generation, any instructions you give the in-app assistant (including short voice recordings you dictate, which we transcribe to text), and the assets the Service produces for you.
- Uploaded media. Files you upload to the Service — images or videos you upload as your own posts, and background images you upload to create custom templates — which we store on our servers so we can display them, render them into your assets, and schedule or publish them at your direction.
- Communications. Information you provide when you contact support or correspond with us.
- Newsletter sign-up. If you subscribe to our mailing list, we collect your email address (and confirm it by double opt-in where applicable) to send you the updates you asked for. You can unsubscribe at any time.
- Payment and billing information. When you subscribe to a paid plan or add funds to your wallet, our payment processor (Stripe) collects and processes your payment card or account details on our behalf. We do not receive or store full payment card numbers; we retain billing records such as your wallet balance, transaction and usage history, subscription tier and status, and the amounts charged.
- Connected social accounts. When you connect a third-party platform — LinkedIn, Facebook and Instagram (via Meta), X (Twitter), Google (YouTube and Business Profile), TikTok, Pinterest, Reddit, Bluesky, Threads, Telegram, or Snapchat — we store the access (and, where provided, refresh) tokens it issues, encrypted at rest, together with the account, profile, Page, channel, or business-account identifiers needed to publish on your behalf. For Bluesky you supply an app password, which we exchange for a session token and do not store; for Telegram you supply a bot token, which we store encrypted. Disconnecting the platform deletes these stored credentials.
- Saved and scheduled content. Posts you save to your library and posts you schedule are stored on our servers — including the post data and any rendered video — so you can revisit, edit, publish, or schedule them.
- Team and organization workspaces. If you create or join a shared organization, resources such as your content library, connected accounts, brand settings, prepaid wallet, and — where enabled — post approvals are shared with the other members of that organization, and we record which member performed an action for audit and approval purposes.
Information collected automatically
- Usage and device data. Log data such as IP address, browser type, pages viewed, and timestamps, used to operate and secure the Service.
- Cookies and local storage. We and our providers use cookies and browser local storage (for example, to keep you signed in and to remember your preferences). See “Cookies and local storage” below.
When you submit a URL, we fetch and process the content of that public web page to generate your assets. Please do not submit content you are not authorized to use, and avoid including sensitive personal information in your inputs.
3. How we use information
We use personal information to:
- Provide, operate, and maintain the Service and generate the assets you request;
- Create and authenticate your account and keep it secure;
- Process payments, manage your subscription and prepaid wallet, and prevent payment fraud;
- Personalize output with your brand settings;
- Respond to your requests and provide customer support;
- Monitor, debug, and improve the Service and develop new features;
- Detect, prevent, and address fraud, abuse, and security incidents;
- Send you newsletters and product updates where you have opted in, which you can unsubscribe from at any time; and
- Comply with legal obligations and enforce our terms.
4. AI processing of your content
To generate assets, the source content and instructions you provide are sent to our third-party AI provider, Google (Gemini, Imagen, and speech-to-text and text-to-speech services), acting as our processor. This includes short voice recordings you dictate to the in-app assistant, which are transcribed to text. Your inputs and outputs are processed to return results to you. We do not use the content you submit to train our own models. Google’s processing of data submitted through its paid API is governed by its applicable terms and data-protection commitments.
5. Legal bases for processing (EEA/UK)
If you are in the EEA or UK, we rely on the following legal bases under the GDPR:
- Performance of a contract — to provide the Service you request and manage your account;
- Legitimate interests — to secure, maintain, and improve the Service, where not overridden by your rights;
- Consent — where required, for example for certain cookies or optional communications (you may withdraw consent at any time); and
- Legal obligation — to comply with applicable law.
8. Data retention
We retain personal information for as long as needed to provide the Service, maintain your account, comply with our legal obligations, resolve disputes, and enforce our agreements. When information is no longer needed, we delete or de-identify it. You may request deletion as described under “Your privacy rights.”
Posts you create are saved to your library and are automatically deleted after a short period (currently a few days) unless you keep or schedule them. Posts you keep or schedule, and any media stored to publish them — including images or videos you upload as your own posts — are retained until you delete them or close your account. Background images you upload for a custom template are retained until you delete that template or close your account. Tokens for a connected social account are retained until you disconnect that platform.
Generated media and uploaded files are stored with a third-party object-storage provider (Cloudflare R2). Narrated videos are retained for a plan-specific window: shorter windows apply during the free trial, and longer windows for paid subscribers (Starter and Pro). After the applicable window, video files may be permanently deleted. We encourage you to download any content you wish to keep before the retention period expires.
9. Data security
We implement reasonable technical and organizational measures designed to protect personal information against unauthorized access, loss, or misuse, including encryption in transit and access controls. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
10. International data transfers
We and our providers may process and store personal information in the United States and other countries that may have different data-protection laws than your jurisdiction. Where we transfer personal data out of the EEA or UK, we use appropriate safeguards such as the European Commission’s Standard Contractual Clauses (and the UK Addendum) or other lawful transfer mechanisms.
11. Your privacy rights
EEA and UK residents
Subject to applicable law, you have the right to access, correct, delete, or receive a portable copy of your personal data; to restrict or object to certain processing; and to withdraw consent. You may also lodge a complaint with your local supervisory authority.
California residents (CCPA/CPRA)
In the preceding 12 months we may have collected the following categories of personal information: identifiers (e.g., name, email, IP address), customer records, commercial information, internet or network activity, and the content you submit. We collect this information for the business purposes described above and disclose it to the service providers listed above. You have the right to:
- Know and access the personal information we have collected about you;
- Delete personal information, subject to legal exceptions;
- Correct inaccurate personal information;
- Opt out of the “sale” or “sharing” of personal information — note that we do not sell or share personal information as those terms are defined under the CCPA/CPRA;
- Limit the use of sensitive personal information (we do not use sensitive personal information for purposes that require an opt-out); and
- Not receive discriminatory treatment for exercising your rights.
Other U.S. state residents
Residents of states such as Virginia, Colorado, Connecticut, Utah, Texas, Oregon, and other states with comprehensive privacy laws may have similar rights to access, correct, delete, and obtain a copy of their personal data, and to opt out of targeted advertising, sale, or certain profiling. We do not sell personal data or use it for targeted advertising.
How to exercise your rights
To make a request, email admin@emtsco.com or use our contact page. We will verify your request and respond within the timeframe required by applicable law. You may use an authorized agent where permitted. If we deny your request, you may appeal by replying to our response.
12. Children's privacy
The Service is not directed to children under 16, and we do not knowingly collect personal information from children under 16 (or under 13 where COPPA applies). If you believe a child has provided us personal information, contact us and we will delete it.
13. Third-party links and content
The Service may link to or process third-party websites (for example, an article URL you submit). We are not responsible for the privacy practices of those third parties, and this Policy does not apply to them.
14. Changes to this Policy
We may update this Policy from time to time. When we do, we will revise the “Last updated” date above and, where required, provide additional notice. Your continued use of the Service after changes take effect constitutes acceptance of the updated Policy.
15. Contact us
If you have questions about this Policy or our privacy practices, contact us at admin@emtsco.com or emtsco, Maryland, USA. You can also reach us through our contact page.
