Privacy Policy

Last updated: 27 September 2026 (effective the same day)

This policy explains what information CrossPost collects, why, how it is protected and how you can delete it. CrossPost (crosspost.virelity.com) is operated by Virelity Inc. ("Virelity", "we", "us"), which is the controller responsible for your information. Questions and complaints: deon.menezes@virelity.com.

1. Summary

2. Information we collect

From TikTok, when you sign in or connect TikTok

CrossPost uses TikTok Login Kit and the TikTok Content Posting API and asks for these permissions (scopes):

ScopeWhat we getWhy
user.info.basicYour TikTok open ID (an app-specific account identifier), display name and avatar image link.To create your CrossPost account and show which TikTok account you are signed in as.
video.uploadPermission to upload a video to your TikTok drafts (inbox).For the "Send to TikTok drafts" option.
video.publishPermission to publish a video to your profile, and access to your current posting settings: your TikTok username and nickname, the "who can view" options available to you, whether comments, Duet and Stitch are turned off for your account, and the longest video you can post.To post directly to your profile and to show the correct options on the posting screen. The posting settings are fetched fresh each time and are not stored, except your username, which we keep to link to your posted videos.

TikTok also gives us an access token and a refresh token, their expiry times and the list of permissions you granted. We never receive your TikTok password.

From Google, when you continue with Google or connect YouTube

CrossPost uses YouTube API Services. By connecting YouTube you agree to the YouTube Terms of Service. CrossPost asks for these Google permissions:

ScopeWhat we getWhy
openidYour Google account identifier (the OpenID "subject", a number). We do not ask for or store your email address.So you can sign back in to CrossPost with Google.
youtube.readonlyYour YouTube channel ID, channel title, handle and avatar link; and, only after an interrupted upload, the newest items of your channel's uploads list.To show which channel you are posting to before you publish, and to check whether an interrupted upload already arrived so CrossPost never uploads the same video twice.
youtube.uploadPermission to upload videos to your channel.To upload the video you select, with exactly the title, description, tags, visibility, made-for-kids and altered-content settings you enter. CrossPost never edits, deletes or reads your other videos.

Google also gives us an access token and a refresh token, their expiry and the list of permissions you granted. We never receive your Google password.

From Instagram, when you continue with Instagram or connect it

CrossPost uses the Instagram API with Instagram Login and asks for instagram_business_basic and instagram_business_content_publish. We receive your Instagram professional account's user ID and app-scoped ID, username, name, profile picture link and account type (Business or Creator), and an access token with its expiry. We use them to show which account you are posting to, to check that it is a professional account, to refresh the token, and to publish the Reels you choose with the caption and settings you enter.

When you post a video

Technical information

Like any website, our hosting provider processes technical request data such as IP address, browser type and the pages requested, and keeps short-lived logs for security and troubleshooting. Our logs never contain access tokens, authorization codes or signed storage links.

Cookies

CrossPost uses only strictly necessary cookies, and no advertising or analytics cookies:

3. How we use information

We use the information above only to provide CrossPost: to sign you in, show which accounts are connected, display the posting options each platform makes available to you, upload and publish the videos you choose with the settings you choose, report their status, keep the service secure and prevent abuse (for example rate limits and daily upload caps), and respond to you. We do not use platform data for advertising, profiling, or any purpose other than the features you use, we do not sell or rent it, and we do not use it to train AI models.

CrossPost's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

4. How long we keep it

5. How we protect it

6. Who we share it with

We share information only with the platform you post to, and with the service providers that run CrossPost:

We may also disclose information if required by law or to protect the rights and safety of our users or others. If Virelity is involved in a merger or acquisition, this policy will continue to apply to your information.

7. Disconnecting platforms and deleting your data

You can delete your data at any time (see also Data deletion):

Deleting your CrossPost data does not remove videos you already posted. Manage those in each platform's app.

8. Your rights

Depending on where you live (for example under the GDPR, UK GDPR or California law), you may have the right to access, correct, delete or receive a copy of your information, to object to or restrict its use, and to complain to your data protection authority. Our legal basis for processing is performing our contract with you (providing the service you asked for) and our legitimate interest in keeping it secure. You can disconnect platforms and delete your account yourself in Settings, use the data deletion page, or email us to exercise any right.

9. International transfers

CrossPost's servers and storage are in the United States. By using CrossPost your information will be processed there, with the protections described in this policy.

10. Children

CrossPost is not directed at children under 13 (or under 16 where the law requires a higher age) and we do not knowingly collect information from them. If you believe a child has used CrossPost, contact us and we will delete the data.

11. Changes

We will post any changes on this page with a new "Last updated" date, and tell you in the app about significant changes.

12. Contact

Virelity Inc., CrossPost. Questions and complaints: deon.menezes@virelity.com.