Privacy Policy
Last updated: September 2026
Viral (“we”, “us”) operates the Viral app and getviral.social. This policy explains what we collect, how we use it, and your choices.
Information we collect
- Account details you provide — name, username, email, and (if you choose to verify by SMS) your mobile phone number.
- Content you create — messages, posts, media, and profile information.
- Device & usage data needed to operate the service (e.g. app version, push tokens for notifications and calls).
How we use your phone number
If you verify your account by SMS, your mobile number is used only to send one-time verification codes (OTP). We do not use it for marketing. See our SMS Terms & Consent for details on message content, frequency, and opt-out.
How we share information
We do not sell your personal information. We share data only with service providers that help us operate Viral (for example, our SMS and email delivery providers), and only as needed to provide the service or as required by law. Your mobile number and consent are never shared with third parties for their own marketing.
Deleting a conversation: three different things
“Delete” means three different operations in Viral, and they are not interchangeable. The app asks you which one you mean.
- Delete for me. This is the default. It removes the conversation from your view — your inbox, your archive, your pins — and sets a cut-off so old messages do not reappear if the chat starts again. It deletes nothing. The messages stay in our database and on the other person’s device.
- Delete for everyone, in a direct message. This is a request, not an instruction. Asking for it records your consent and asks the other participant for theirs. Only when everyone in the conversation has agreed is anything erased. If they decline, nothing of theirs is touched and you can still delete your own copy. One person cannot destroy another person’s record of a conversation.
- Delete for everyone, in a group. The owner or an admin can erase the group for everyone. Ordinary members cannot, and asking a thousand people for consent would mean never deleting anything.
- Clear history. Erases messages up to a cut-off and leaves the conversation itself standing. Clearing only your own view needs nobody’s permission; clearing it for everyone goes through the same consent gate as deleting for everyone.
There is one exception to the consent rule, and it is deliberate: an account being deleted erases its own side without asking anybody. Your right to erase your own account cannot be held hostage by someone who never answers.
What an erasure actually removes
When a conversation is erased, this is what is deleted, and it is more than the chat disappearing from a list:
- The conversation and every message in it — including the messages held in the separate stores that large groups and forum topics use, and the reactions and read receipts that travel inside each message.
- The membership records, and any outstanding delete-for-everyone requests attached to the conversation.
- The end-to-end-encrypted copies our delivery service was still holding for devices that had not collected them, and the group state that routed them.
- The photos, videos and files themselves — the stored objects, not just the links to them — together with their signed provenance records and the saved-media pointers to them. Media that another surviving message still points at is kept, because its file is staying.
- The message previews stored in notification records and push logs, and the search vectors built from the message text. A deleted conversation whose words are still readable in a notification list has not been deleted.
- The conversation’s encryption keys, which are overwritten and then destroyed rather than simply deleted. The erasure is recorded in a receipt log, keyed by a hash that cannot be turned back into the conversation.
The conversation, its messages and its membership are deleted in a single atomic step, so there is no state where the chat is gone from your inbox but the messages are still in the database. The rest — the files, the notification previews, the vectors — is written to a work journal first and swept immediately afterwards, so a crash mid-way delays that work rather than losing it. For as long as that sweep runs, those derived copies can outlive the conversation.
Disappearing messages
A conversation can be set to delete its own messages after 1 hour, 8 hours, 24 hours, 7 days, 30 days or 90 days. Ninety days is the ceiling: anything longer would be a retention policy wearing a privacy feature’s clothes.
- Anyone in the conversation can set the timer, and a change is announced in the transcript. That announcement never disappears, so a chat cannot start forgetting silently.
- When a message expires, the quoted copy of its text inside anybody’s reply is removed as well. The reply stays where it is and shows that the message is no longer available.
- Messages that expire also take their stored notification previews, push-log entries and search vectors with them.
- A forwarded message is a new message with its own timer. The original’s timer does not follow it, and forwarding is therefore a way to keep something the original chat was going to forget.
- A timer deletes the message from the live database, and that is what it promises. It does not reach into backups: our database keeps a point-in-time restore window, and a restore to a moment before the timer ran out can still contain the message until that window rolls past it. We would rather say this than let a timer be read as a guarantee it cannot make.
The crypto wallet
The wallet is non-custodial. Your recovery phrase and the keys derived from it are made on your device and stay there. We do not hold them, we cannot reconstruct them, and we cannot move your crypto — which also means we cannot recover it for you if you lose your phrase.
That is not a promise we ask you to take on trust. Every field the server is allowed to store about the wallet is declared by name in the code, and a build check refuses to compile a field whose name suggests key material — a private key, a seed, a mnemonic, a passphrase, or an opaque blob one could hide inside. A change that broke this claim would fail the build before it could ship.
What we do store:
- Your wallet addresses, and the fact that you proved you hold them. An address is public by nature — it is what you give someone so they can pay you.
- A copy of your transaction history. Every entry is already public on the blockchain; what is ours is the copy, keyed to your account so the app can show it to you quickly. You can switch this off in the wallet’s settings, and then we keep no index of your history at all.
- Cached balances and token prices, so the app does not have to ask the network on every screen.
- Swap quotes and completed swaps, including the fee we showed you before you signed. We keep the disclosed figures precisely so a dispute about a fee can be settled against what you were actually told.
- Outstanding approvals — standing permissions you have given a contract to spend a token — so the app can list them and let you revoke them.
When you delete your account, all of this is deleted with it, with one exception we would rather name than bury: completed swaps are kept, with your identity removed. They are a financial record, they are covered by the same retention rule as the money records below, and what remains cannot be traced back to you.
What we keep after an erasure, and why
Four things survive an erasure. This is the entire list, and each one is narrower than it sounds.
- Child-safety evidence. If something in a conversation was reported for child safety, that material is kept as evidence for the authorities. Only what was actually reported under the child-safety category — not the whole conversation. It is access-controlled, held for at least 90 days, and deleted when the matter closes. See Child safety.
- Money records. Records of money you sent or received are kept, so the books balance and a dispute can still be settled. The record is amounts, dates and who paid whom. Never what was said: a message attached to a payment is deleted with the conversation.
- The moderation log. Moderation actions stay in a public, tamper-evident log that nobody can rewrite, including us. Its entries hold hashes and categories only — no message, no name, nothing that points back to you.
- Proof of a reported message. If someone reported a message you sent them, the proof that you sent it is kept. The proof is a cryptographic token and the sender’s id; the message text itself is deleted with the conversation. A sender who could erase the proof of what they sent would make reporting worthless.
Nothing is added to that list without changing this page.
What deletion cannot reach
A privacy feature that overpromises is worse than none, so here is what we cannot do. These are limits of the system, not of our effort.
- We cannot stop a screenshot, or someone photographing the screen with another device.
- We cannot delete a copy from a device that never comes back online. A phone that received a message and then went dark keeps it.
- We cannot erase anything from a blockchain. A transaction you made is on a public ledger that we do not control and nobody can rewrite. Deleting your account removes our copy of your history; it does not, and cannot, remove the transactions themselves.
- We cannot un-send a notification your phone has already shown, and today the notification we send can contain the text of the message — including in a conversation with a timer. We are changing that; until we have, this is what is true.
- We cannot reach a copy somebody forwarded before the original expired or was deleted.
- Deletion is not instantaneous everywhere. Our database keeps a continuous point-in-time restore window and we take periodic backups; a deleted message can survive in those until the window rolls past the deletion, and in the database’s own internal logs until they roll. Restoring a backup taken before a deletion can bring ordinary deleted content back, which is why we destroy conversation keys and record receipts as well as deleting rows.
- Destroying a conversation’s keys does not yet make its old content unreadable. Key destruction runs on every erasure today, and the encryption of stored content under those keys is still being rolled out. Until that is finished, our promise for the copies we cannot chase is the one above — the backup window — and not “unreadable ciphertext”. We would rather say so than imply otherwise.
Data retention & security
We keep your information for as long as your account is active, and use technical and organizational measures to protect it. You can delete individual messages, clear a conversation, erase a conversation, or delete your whole account — see Delete your account for exactly what that last one does and does not do today.
Your choices
You can update your profile, manage privacy settings in the app, set a disappearing-message timer per conversation, opt out of SMS by replying STOP, and delete your account from Profile → Settings → Account or by contacting us.
Contact
Questions? Email support@getviral.social. See also our Terms of Service.