Privacy policy.
This Policy explains what data Viuz collects, why we collect it, who we share it with, and how you can control it. We follow LGPD (Brazil) and, where applicable, GDPR principles.
Data controller
Zeit Capital LTDA · CNPJ 52.988.658/0001-57, Brasília, DF, Brazil, is the data controller for personal information processed through Viuz. Privacy questions and data requests: privacy@viuz.ai.
What we collect
Account data: your email address, your name, and the authentication tokens that keep you signed in. Brand inputs: everything you give us to work with, including briefs, posts, captions, brand guidelines, colours, fonts, images and video you upload, and the public social profile you ask us to read. Publishing credentials: the access tokens Instagram, TikTok, Threads, X and LinkedIn issue when you connect an account, used only to publish on your behalf and to read back the performance of what we published. Billing data: your plan, your subscription state and your billing country; card numbers are handled by Stripe and never reach our servers. Product analytics: page views, feature usage and signup funnel events, described in detail below. Contact preferences: which updates you agreed to receive, by email or by phone, and a phone number if you choose to give us one. Support messages you send us.
Why we process it
To deliver the service you signed up for, which is our contractual basis: generating posts, rendering them, scheduling them, and publishing them to the accounts you connect. To keep the platform secure, to prevent abuse, and to measure and improve the product, all of which rest on our legitimate interest. To comply with tax, accounting and other legal obligations. Optional analytics collected in your browser runs on your consent alone, and nothing else does.
Updates, notices and news
Viuz can send you product updates, service notices and news and offers, but only if you opt in, and every one of them starts switched off. You choose them in Settings › Notifications, at the end of onboarding, or on a card on your home screen, and your choice is our legal basis: your consent under LGPD article 7, I, and GDPR article 6(1)(a) where it applies. Email updates go to the email address you sign in with. You may also give us a phone number and choose which of the same updates you would accept by phone. We do not verify that number with a code today, so we cannot confirm it is yours, and we do not send anything to it: no SMS, no WhatsApp, no calls. Before we ever send a message to a phone, we will update this Policy and name the provider that delivers it, and a number that was never verified will not be treated as confirmed. Your phone number is stored encrypted and is used for nothing else. Messages that are part of the service itself, such as billing, security, team invitations, publishing failures and your trial, are not updates you opt into, and they keep reaching you whatever you choose here. You can withdraw any consent at any time in Settings › Notifications, and every update email carries an unsubscribe link that works with one click, without signing in. Withdrawing stops future messages and does not affect what was sent before. For each choice you make we keep a record of what you chose, when, the version of the wording you saw, and the IP address and browser it came from, so we can show that you agreed, and when you stopped.
Google user data and Limited Use
Viuz offers an optional Google Drive import for your own images and video, in two ways, and this section describes both. By default, when you pick a file to import, Google shows you its own file picker inside your browser and grants Viuz access to the specific files you select, under the drive.file scope. That scope covers the files you pick in that picker session only, never the rest of your Drive. The access token Google issues for that picker session stays in your browser: it is never sent to our servers and never stored anywhere, we run no background job against your Drive, and we cannot open a file you did not choose there. If you instead connect a Google Drive account to a brand, so you can browse your recent Drive files inside our own screens rather than opening the picker every time, the grant is broader and we hold something for it: connecting sends an authorization code to our server under a read-only drive.readonly scope, and from it we hold an encrypted refresh token for that connection, one per brand connection, plus a short-lived access token, until you disconnect it. What we read once an account is connected is limited to file names, folder structure and thumbnails when you browse, and the bytes of the specific file you choose to import; nothing is read in the background either way, because there is no folder watcher and no sync, connected or not. A list of your Drive files is cached for 60 seconds so a fast reload does not cost a second call; that list is held only in a short-lived server cache, never written to our database, and the cache expires on its own. Your browser, or our server on your behalf when you import through a connected account, copies the bytes of the file you selected once, and from then on that copy lives in our storage exactly like a file you had uploaded from your computer, under the same scanning, quota and retention rules. It is a copy and not a sync: deleting the file in Drive does not delete our copy, and deleting our copy does not touch Drive. Every import also carries a small marker naming Google Drive as its source and identifying which file and version it came from, so a Drive import can be told apart from an upload; that marker is metadata about the copy, not a live link back to Drive. We do not read your Drive file names, contents or metadata for any purpose beyond what this section describes. A connection is kept until you disconnect it, delete the brand, or delete your Viuz account. Disconnecting it and deleting your account each revoke the grant at Google first and delete the encrypted token second, in that order, so a failed revoke never leaves a phantom deletion behind it; deleting the brand deletes that connection row on its own, without revoking anything at Google first, so a grant left behind by a deleted brand stays live until you revoke it yourself at myaccount.google.com/permissions or delete your account. Inside Viuz, any member of that brand can see that a connection exists; browsing the files it lists is limited to that brand's owners, admins and editors, and importing a file needs its own content-write capability, a stricter gate than plain uploading carries today; our own staff can reach it only the way the Security section describes for every production system, limited to the people who operate it, never to browse your files for its own sake. Viuz use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements (developers.google.com/terms/api-services-user-data-policy). Specifically: we do not transfer Google user data to third parties except as needed to provide or improve this feature, to comply with applicable law, or as part of a merger or acquisition; we never use it for advertising; we do not allow humans to read it, except with your explicit permission, for security purposes, to comply with applicable law, or where the data has been aggregated and anonymised; and we never use it to develop, improve or train generalised artificial intelligence or machine learning models. If you later use a feature that acts on an imported image, such as an AI edit of a slide, that image is sent to the AI provider performing the edit and to nobody else, as described in the next section. To remove an imported copy, delete it from your media library; to revoke a Drive connection, disconnect it from the Connections tab on that brand, use Google's own page at myaccount.google.com/permissions, or delete your account, and any of the three revokes the grant. You can also write to privacy@viuz.ai for anything this section does not cover.
How AI providers process your content
Generating a post means sending your brief, your brand voice and your brand guidelines to an AI provider, today Google Gemini, which returns the copy and the imagery we compose into your slides. If you use a feature that acts on an image you supplied, that image is sent to the same provider to perform the edit. We send only what the feature needs, we receive the result back, and we do not use your content, or anything you import from Google Drive, to train models of our own. Background removal runs on our own infrastructure, so your image is not sent to a third party for it. AI output is generated text and imagery: review it before you publish, because what goes out under your handle remains yours.
Public profiles we read without an account
Anyone can ask our site for a free read of a public Instagram or TikTok profile without signing up. For that read we fetch, through Apify, the public profile and up to 12 recent public posts: the handle, display name, bio, profile picture, follower count, and each post's type, date, caption and public counts. We keep the read so its link keeps working, including the numbers it computed and the short lines it quotes from the bio or captions. To compare a read with its market, we also keep niche panels: short lists of public business and creator accounts in a niche, chosen by hand and read once through Apify. A panel stores each account's handle, its follower count rounded to two significant figures and numbers computed from its recent public posts (posting rhythm, response per post, share of video, share of captions with a call to action, whether the bio carries a link). It never stores a caption, a bio, a post or a picture. A read may name up to three panel accounts as accounts to look at, with those numbers and a link to their public profile. We process this public data under legitimate interest: helping businesses understand how public accounts in their niche post. If your account is in a panel or was read and you want it removed, write to privacy@viuz.ai from any address naming the handle, and we remove it within 15 days.
Who we share it with
We use sub-processors to run the service and give each one only what it needs. Supabase hosts our database and authentication. Railway runs our API, our background workers and our queue. Cloudflare serves the web app and stores your media. Google Gemini generates the text and imagery in your posts. Perplexity powers the news and research features. Apify reads the public Instagram and TikTok profiles you ask us to analyse, the ones read on our free profile read, and the ones in our niche panels. Stripe processes payments. Mixpanel receives product analytics. Sentry receives error reports. Crisp powers the in-app support chat. Cloudflare also sends the emails we send you, including the updates you opt into. We do not sell your data. We do share limited data with Meta Platforms to measure and improve our own ads on Facebook and Instagram: when you sign up, start a trial or start a paid plan, our servers tell Meta, sending your email address and account id hashed (SHA-256) before they leave us, the IP address and browser details of your visit, and Meta’s click and browser identifiers if you accepted marketing cookies. Meta uses this to report which of our ads led to sign-ups and to show our ads to people likely to be interested. It never includes your posts, captions, prompts or brand data. Turning off server analytics in Settings › Notifications stops it. Analytics reaches Mixpanel two ways, on different legal bases. Analytics collected in your browser, the part that uses cookies and local storage, including the interaction data and the masked session recordings described under Cookies, is sent only when you accept optional cookies. Records of actions our own servers carry out, such as a post being published to Instagram or a subscription starting, are sent under legitimate interest so the service can be measured and kept working; they carry no cookies and contain only identifiers, including a device identifier that lets us link a visit you made before you signed up to the account you later created, plus counts and timestamps, never the text of your posts, captions or prompts. Mixpanel also keeps one profile per account, holding your email address and your display name alongside the plan and usage facts already described here, so our own team can recognise a real customer rather than a bare id.
Your rights
Under LGPD, and under GDPR where it applies, you can confirm that we process your data, access it, correct it, export it, ask us to delete it, restrict or object to a processing activity, and withdraw a consent you gave. Most of this you can do yourself: your content and your connected accounts are editable and deletable in the dashboard, and deleting a brand deletes its posts and media with it. For anything else, write to privacy@viuz.ai. You can withdraw consent for browser analytics at any time from the Cookie preferences control on this page or in Settings › Notifications, withdraw consent for updates in Settings › Notifications or through the unsubscribe link in any update email, and you can object to the server-side analytics described above, which does not depend on cookies, by writing to the same address. You may also complain to the ANPD in Brazil or to your local supervisory authority.
Security
Data is encrypted in transit with TLS and encrypted at rest by our hosting providers. Access to production systems is limited to the people who operate them. A phone number you give us is additionally encrypted with our own key before it is stored. Images you upload or import are scanned for malware and stripped of EXIF metadata, including any GPS coordinates, before they are stored. No system is perfectly secure: if a breach affects your personal data we will notify you and the ANPD as the law requires.
Retention
Account data is kept while your account is active, plus a short window for dispute resolution and the periods Brazilian tax and accounting law require. Posts, media and brand data are deleted together with the brand they belong to. Your update preferences and your phone number are kept until you change or remove them, or delete your account. The record of each consent you gave or withdrew is kept for two years after it was made, to demonstrate it, including after you withdraw it or delete your account. Analytics events roll off after 24 months. Deleting your account removes your personal data from our production systems; backups age out on their own schedule.
International transfers
Viuz is operated from Brazil and most of our sub-processors are in the United States or the European Union, so your data is transferred internationally. Transfers rely on the mechanisms LGPD and GDPR allow: contractual clauses with each provider, and adequacy decisions where one exists.
Cookies
Essential cookies keep you signed in, remember your language and, on this device, your most recent free profile read. Optional analytics cookies power Mixpanel and are set only when you accept them. With that same consent, we also record how you use the browser: clicks, including rage clicks and dead clicks that flag something did not work, how far you scroll, and how long you spend on a page, plus a masked recording of a sample of visits, where every block of text and everything you type is hidden and images, video and canvas elements are never captured. Optional marketing cookies are a separate choice: if you accept them, the Meta Pixel loads and sets Meta’s cookies (_fbp, _fbc) so Meta can measure which of our ads brought you here. Accept all turns on both; Customize lets you choose each one. You can change your choice at any time from the Cookie preferences control on this page or in Settings › Notifications, and rejecting or withdrawing stops all of this immediately. The server-side records described under "Who we share it with" use no cookies and are governed separately.
Children
Viuz is a tool for businesses and creators and is not directed at children. You must be 18 or older to hold an account. We do not knowingly collect personal data from children; if you believe a child has given us data, write to privacy@viuz.ai and we will delete it.
Changes
We may update this Policy. Material changes will be announced by email or in-product at least 30 days before they take effect, and the effective date at the top of this page always shows the version in force.
Contact
Zeit Capital LTDA, CNPJ 52.988.658/0001-57, Brasília, DF, Brazil. Privacy and data requests: privacy@viuz.ai. Everything else: hi@viuz.ai. We answer data requests within the 15-day deadline LGPD sets.
Back to home