Hashed passwords
Passwords are hashed with bcrypt (cost factor 12) before they are stored. We never store or log plain-text passwords.
Signed sessions
Sign-in sessions are signed tokens issued by NextAuth. Signing out clears the session cookies on your device.
OAuth with state & PKCE
Connecting Instagram, Facebook, TikTok or Pinterest uses OAuth. Each flow is protected with a one-time state value and, where supported, PKCE — we never ask for your social media passwords.
Per-account data isolation
Every API request is checked against your session, and records such as products, watchlists, wallets and stream plans are scoped to your user ID.
Safe website scanning
Store and product URLs you submit are validated before we fetch them. Private network and internal addresses are blocked to prevent server-side request forgery.
Content Security Policy
Pages are served with a Content Security Policy that restricts which origins may load scripts and connect to APIs.
Crypto wallets
The Add Wallet feature only stores public information you type in: a wallet name, network, optional public address and the amounts you hold. IgniteViral will never ask for a private key or seed phrase — if anyone does, it is not us.
What you can do
- Use a unique, strong password for IgniteViral.
- Disconnect social accounts you no longer publish to.
- Sign out on shared devices.
Reporting a vulnerability
If you believe you have found a security issue, please report it privately through the contact page with steps to reproduce. Please do not access other users’ data or disrupt the service while testing. We will acknowledge your report and keep you updated while we fix it.
Privacy
For what data we collect and your rights over it, see the Privacy Policy and Cookie Policy.