Browse documentation

Trust

Security and privacy

The connector receives only the access needed to fulfill authorized research requests.

Authentication

ViralShark uses OAuth authorization with PKCE. Access tokens are scoped to the connector and can be revoked. The AI client never receives the user’s ViralShark sign-in credentials.

Data used by the connector

  • The request sent from the authorized AI client.
  • ViralShark research evidence needed to answer that request.
  • Account identity, plan, and usage information needed to authorize the operation.
  • Operational metadata used for security, reliability, and abuse prevention.

Data boundaries

ViralShark does not sell personal information. Connector access does not make private account data public, and protected operations remain subject to the same ownership and plan checks as the web app.

Policies and support