Privacy Policy
Last updated: 27 September 2026 (effective the same day)
This policy explains what information CrossPost collects, why, how it is protected and how you can delete it. CrossPost (crosspost.virelity.com) is operated by Virelity Inc. ("Virelity", "we", "us"), which is the controller responsible for your information. Questions and complaints: deon.menezes@virelity.com.
1. Summary
- You sign in with TikTok, Google (for YouTube) or Instagram, and connect the platforms you want to post to. We receive your basic profile on each platform and permission to publish the videos you choose.
- Access tokens are encrypted at rest (AES-256-GCM) and never sent to your browser.
- Your video is stored privately only while it is being sent to the platforms you picked. It is deleted as soon as every platform has it, and always within 24 hours of upload.
- We do not sell your information, show ads, build profiles, use analytics trackers, or use your content or platform data to train AI models.
- You can disconnect any platform, or delete your CrossPost account and all its data, at any time.
2. Information we collect
From TikTok, when you sign in or connect TikTok
CrossPost uses TikTok Login Kit and the TikTok Content Posting API and asks for these permissions (scopes):
| Scope | What we get | Why |
|---|---|---|
user.info.basic | Your TikTok open ID (an app-specific account identifier), display name and avatar image link. | To create your CrossPost account and show which TikTok account you are signed in as. |
video.upload | Permission to upload a video to your TikTok drafts (inbox). | For the "Send to TikTok drafts" option. |
video.publish | Permission to publish a video to your profile, and access to your current posting settings: your TikTok username and nickname, the "who can view" options available to you, whether comments, Duet and Stitch are turned off for your account, and the longest video you can post. | To post directly to your profile and to show the correct options on the posting screen. The posting settings are fetched fresh each time and are not stored, except your username, which we keep to link to your posted videos. |
TikTok also gives us an access token and a refresh token, their expiry times and the list of permissions you granted. We never receive your TikTok password.
From Google, when you continue with Google or connect YouTube
CrossPost uses YouTube API Services. By connecting YouTube you agree to the YouTube Terms of Service. CrossPost asks for these Google permissions:
| Scope | What we get | Why |
|---|---|---|
openid | Your Google account identifier (the OpenID "subject", a number). We do not ask for or store your email address. | So you can sign back in to CrossPost with Google. |
youtube.readonly | Your YouTube channel ID, channel title, handle and avatar link; and, only after an interrupted upload, the newest items of your channel's uploads list. | To show which channel you are posting to before you publish, and to check whether an interrupted upload already arrived so CrossPost never uploads the same video twice. |
youtube.upload | Permission to upload videos to your channel. | To upload the video you select, with exactly the title, description, tags, visibility, made-for-kids and altered-content settings you enter. CrossPost never edits, deletes or reads your other videos. |
Google also gives us an access token and a refresh token, their expiry and the list of permissions you granted. We never receive your Google password.
From Instagram, when you continue with Instagram or connect it
CrossPost uses the Instagram API with Instagram Login and asks for instagram_business_basic and instagram_business_content_publish. We receive your Instagram professional account's user ID and app-scoped ID, username, name, profile picture link and account type (Business or Creator), and an access token with its expiry. We use them to show which account you are posting to, to check that it is a professional account, to refresh the token, and to publish the Reels you choose with the caption and settings you enter.
When you post a video
- The video file, uploaded from your browser to private storage, only so it can be sent to the platforms you picked (see section 4).
- Your caption and per-platform settings: for TikTok, who can view, comments, Duet, Stitch and commercial content disclosure; for YouTube, the title, description, tags, visibility, made-for-kids and altered-content answers; for Instagram, the caption, "also share to feed" and cover frame. In the multi-platform flow they are stored with the post so that each platform can be retried; on the TikTok-only page they are sent to TikTok and not stored.
- Post records: file size, type, duration and dimensions, which platforms you picked, each platform's status and result (for example the link to your post and the platform's post ID, or its error message) and timestamps. This lets the app show progress and your post history.
Technical information
Like any website, our hosting provider processes technical request data such as IP address, browser type and the pages requested, and keeps short-lived logs for security and troubleshooting. Our logs never contain access tokens, authorization codes or signed storage links.
Cookies
CrossPost uses only strictly necessary cookies, and no advertising or analytics cookies:
cp_session: keeps you signed in (signed, HttpOnly, Secure; lasts 30 days or until you sign out).cp_oauth,cp_oauth_youtubeandcp_oauth_instagram(together,cp_oauth*): protect a sign-in or connection against forgery (last 10 minutes and are deleted when it finishes).
3. How we use information
We use the information above only to provide CrossPost: to sign you in, show which accounts are connected, display the posting options each platform makes available to you, upload and publish the videos you choose with the settings you choose, report their status, keep the service secure and prevent abuse (for example rate limits and daily upload caps), and respond to you. We do not use platform data for advertising, profiling, or any purpose other than the features you use, we do not sell or rent it, and we do not use it to train AI models.
CrossPost's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
4. How long we keep it
- Videos are deleted as soon as every platform you picked has them, and always within 24 hours of upload. On the TikTok-only page, videos are deleted as soon as TikTok has received the whole file; if an upload is cancelled or fails, the video is deleted then, and any copy left behind by an interrupted upload is removed automatically within about a day.
- Connected accounts and tokens are kept until you disconnect that platform or delete your account. YouTube channel and Instagram profile details are refreshed from the platform at least every 7 days, so they are never more than 30 days old, and are deleted when you disconnect.
- Post history (records, captions, settings and links) is kept until you delete your account.
- Logs are kept for up to 30 days and contain no tokens.
- Deleted data may remain in our database provider's encrypted backups for up to 7 days before it is overwritten.
5. How we protect it
- All traffic uses HTTPS.
- Access and refresh tokens are encrypted with AES-256-GCM before they are stored in our Neon Postgres database, with keys kept separately from the database. They are used only on our servers and are never sent to your browser.
- Videos are kept in a private storage bucket that is not publicly accessible, under a path tied to your account. When Instagram needs to fetch a video, it gets a signed link to that one file that expires within an hour.
- Session cookies are signed and HttpOnly; state-changing requests require a per-session security token.
- Access to production systems is limited to the Virelity staff who run CrossPost.
6. Who we share it with
We share information only with the platform you post to, and with the service providers that run CrossPost:
- TikTok, YouTube (Google) and Instagram (Meta): each receives the video, caption and settings you chose for it when you post, under its own privacy policy. See the Google Privacy Policy for how Google handles data.
- Vercel Inc.: hosts the website and servers and provides the private video storage (United States).
- Neon: hosts our database (United States).
We may also disclose information if required by law or to protect the rights and safety of our users or others. If Virelity is involved in a merger or acquisition, this policy will continue to apply to your information.
7. Disconnecting platforms and deleting your data
You can delete your data at any time (see also Data deletion):
- Disconnect one platform: in CrossPost, open Settings and press Disconnect on that platform. We revoke CrossPost's access where the platform allows it (TikTok and Google), delete that platform's tokens and account details, and stop any of its posts still in progress.
- Delete everything: in Settings press "Delete my CrossPost account" (on the TikTok page the same action is labelled "Disconnect TikTok and delete my data"). We revoke CrossPost's access with every connected platform, delete any stored videos, and permanently delete your account, tokens and post history immediately.
- In Google: you can revoke CrossPost's access at any time at security.google.com/settings/security/permissions. When you revoke access we delete your YouTube data within 7 days (normally within a day).
- In Instagram: remove CrossPost under Settings, then Apps and websites. Instagram then tells us, and we treat that as a request to delete your Instagram data: we delete it and stop any Instagram posts in progress. You can also send a data deletion request through Meta; we give you a confirmation code you can check on our deletion status page.
- In TikTok: remove CrossPost in the TikTok app (Settings and privacy, then Security and permissions, then Apps and services permissions). This stops CrossPost from accessing your account. To also delete the records we hold, use the buttons above or email us.
- By email: write to deon.menezes@virelity.com and tell us which accounts are connected; we will confirm and delete your data within 30 days.
Deleting your CrossPost data does not remove videos you already posted. Manage those in each platform's app.
8. Your rights
Depending on where you live (for example under the GDPR, UK GDPR or California law), you may have the right to access, correct, delete or receive a copy of your information, to object to or restrict its use, and to complain to your data protection authority. Our legal basis for processing is performing our contract with you (providing the service you asked for) and our legitimate interest in keeping it secure. You can disconnect platforms and delete your account yourself in Settings, use the data deletion page, or email us to exercise any right.
9. International transfers
CrossPost's servers and storage are in the United States. By using CrossPost your information will be processed there, with the protections described in this policy.
10. Children
CrossPost is not directed at children under 13 (or under 16 where the law requires a higher age) and we do not knowingly collect information from them. If you believe a child has used CrossPost, contact us and we will delete the data.
11. Changes
We will post any changes on this page with a new "Last updated" date, and tell you in the app about significant changes.
12. Contact
Virelity Inc., CrossPost. Questions and complaints: deon.menezes@virelity.com.