Security

Security and data handling

ViewTracker is built so your creators never have to hand over account access. This page describes what we collect, where it lives and how it is protected. It describes our practices; it is not a certification.

Last updated 2026-10-02

Public data only, no creator logins

  • ViewTracker tracks public videos and profiles on TikTok, Instagram, YouTube and Facebook. Creators never log in, share passwords or grant access to their social accounts.
  • Metrics come from public pages and public APIs, including the YouTube Data API, collected by our own collector and by third-party public-data providers.
  • Private and deleted videos can't be tracked, because they aren't publicly visible.
  • Creators who submit videos through the creator portal sign in to ViewTracker with an email address, not with a social account.

What we store

  • For each tracked video: its link, caption, thumbnail link, length, author handle and display name, publish time, and timestamped public counts — views, likes, comments, shares and saves where the platform shows them.
  • For tracked profiles: public profile statistics over time. We don't store comment text, messages or anything behind a login.
  • What your team adds: creator profiles (name, optional email and notes), campaigns, spend, report branding, alerts and saved views.
  • Your account: name, email and a password handled by our authentication library, which stores only a salted hash. Email verification is required, password-reset links expire after an hour, and a reset signs out other sessions.

Where it runs

  • The web application is hosted on Vercel.
  • The database and background jobs run on Cloudflare (Workers, Queues and Durable Objects with SQLite storage). Cloudflare keeps point-in-time recovery for the database for 30 days.
  • Transactional email (verification, password reset, invitations) is sent through Brevo.

Payments

  • Subscriptions are processed by Stripe. Card details are entered on Stripe's checkout and customer portal; ViewTracker never receives or stores card numbers.
  • Our billing webhook verifies Stripe's signature before it changes a subscription.

Access controls

  • Workspaces have owner, admin, member and viewer roles. Viewers have read-only access to dashboards and reports.
  • API keys are shown once when created and stored only as a SHA-256 hash. Keys can be revoked at any time.
  • Outgoing webhooks are signed with HMAC-SHA256 so you can verify they came from ViewTracker.
  • Google Sheets sync asks only for access to files it creates. Its refresh token is encrypted with AES-256-GCM, and disconnecting removes it and requests revocation from Google.
  • Our internal operations console uses authenticator-app two-factor sign-in. When our team looks at a workspace to help you, that access is read-only, expires after 15 minutes and is recorded in an audit log.

Deleting data

  • Deleting a video or tracked account removes it together with its snapshot history.
  • Workspace owners can delete a workspace from Settings after cancelling its subscription. This deletes its videos, accounts, snapshots, creators, campaigns, reports, alerts, API keys, webhooks and integrations.
  • Records of our own staff actions and billing events are kept for accounting and audit purposes without the link to the deleted workspace. Database recovery points expire within 30 days.

Reporting a security issue

If you believe you have found a vulnerability, email hello@viewtracker.ai with “Security report” in the subject, the steps to reproduce it and the affected URL. Please don't access other customers' data or degrade the service while testing. For questions about your own data or a deletion request, use the same address.

Related: Pricing FAQ · API documentation