Skip to content
Virio
Back to Virio

Virio legal

Privacy Policy

This policy explains what data Virio processes when you use the website, mobile application, and related API, and the choices available to you.

Effective date
August 11, 2026
Operator
Andrei Lashkevich, Poland
01

Who controls your data

Virio is operated by Andrei Lashkevich in Poland. For data-protection questions or requests, contact lashket@gmail.com.

This policy applies to the Virio website, mobile application, API, and support communications. Services provided by Meta, Threads, Apple, Google, OpenAI, or other third parties are governed by their own privacy notices.

02

Data we collect

We collect only the information needed to provide and secure Virio.

  • Account data: email address, display name, password hash, language, timezone, and settings.
  • Connected Threads data: platform user ID, username, connection status, encrypted access token, token expiry, and approved permissions.
  • Creator content: topics, keywords, saved signals, generation prompts, generated ideas, drafts, approvals, schedules, published post references, and performance analytics.
  • Public signal data: limited public post previews and metrics needed to score topics selected by you. Virio does not collect private Threads content.
  • Technical and security data: session identifiers, request IDs, timestamps, job status, error diagnostics, and privacy-safe product events. We do not use advertising trackers.
  • Support data: messages you send to us and the contact details needed to reply.
03

Why we use data

We process data to provide the service, secure accounts, improve reliability, and meet legal obligations.

  • Contract: create your account, connect requested services, generate and store drafts, schedule approved posts, and show analytics.
  • Consent: connect an optional Threads account, grant platform permissions, and choose optional communications. You may withdraw consent by disconnecting or contacting us.
  • Legitimate interests: prevent abuse, debug failures, measure product reliability, and improve the workflow without building advertising profiles.
  • Legal obligation: respond to valid legal requests and maintain records required by law.
04

AI and connected services

When you request generation, Virio sends the prompt, selected public signal context, writing preferences, and necessary draft context to the configured OpenAI service. Virio does not send your password or Threads access token to OpenAI. Review generated text before using it; AI output may be inaccurate.

When you connect or publish to Threads, Virio uses Meta’s official interfaces and the permissions you approve. Meta processes that activity under its own terms. Email delivery may be handled by Resend when password-reset email is enabled. Infrastructure providers process encrypted or access-controlled data only to host and operate Virio.

05

Sharing and international transfers

We do not sell personal data. We share it only with service providers needed to operate Virio, with a connected platform at your request, during a lawful business transfer, or when required by law. Providers are expected to use data only for the agreed service and protect it appropriately.

Some providers may process data outside Poland or the European Economic Area. Where required, transfers rely on an adequacy decision, Standard Contractual Clauses, or another lawful safeguard. Contact us for information about safeguards relevant to your data.

06

Retention

Account content is kept while your account is active and deleted when you use permanent account deletion, subject to short-lived backups and records we must keep by law. Access sessions expire after 30 days; password-reset tokens expire after 30 minutes; Threads authorization state expires after 10 minutes; cached trend results normally expire after 12 hours.

Disconnecting Threads stops further use of that connection. Connection records may remain until account deletion for security and audit purposes. You may ask us to erase them sooner. De-identified operational events may be retained to understand reliability, and server backups may persist for a limited rotation period before being overwritten.

07

Security

Virio uses access controls, password hashing, encrypted transport, rate limits, rotating sessions, ownership checks, and AES-256-GCM encryption for connected-account tokens. Secrets are kept on the server and are not embedded in the mobile app.

No system can guarantee absolute security. If you believe your account or data is at risk, contact us promptly at lashket@gmail.com.

08

Your choices and rights

Depending on where you live, you may request access, correction, export, deletion, restriction, objection, or portability, and may withdraw consent. The app provides export, disconnect, and account-deletion controls. You can also email lashket@gmail.com. We may verify your identity before acting.

  • You may lodge a complaint with Poland’s Personal Data Protection Office at https://uodo.gov.pl or with your local supervisory authority.
  • You may control platform permissions in your Meta account as well as in Virio.
  • You may opt out of non-essential emails at any time. Essential security and service messages may still be sent.
09

Website, children, and changes

The public Virio website does not use advertising or analytics cookies and does not contain a tracking form. A language choice is handled in your browser and is not sent to an advertising network. Standard hosting logs may record an IP address and user agent for security and delivery.

Virio is not directed to children under 16. If you believe a child has provided personal data, contact us so we can remove it.

We may update this policy when the service or law changes. We will post the revised date and provide additional notice when a change materially affects your rights.