EzCoder

Privacy Policy

Last updated: July 22, 2026

See also our Cookie Policy, Terms of Service, Service Providers page, and Data Processing Addendum.

1. Introduction

EzCoder, Inc. ("EzCoder", "we", "us", or "our") operates the EzCoder platform at ezcoder.dev, an AI-powered tool for building, previewing, deploying, and marketing web applications. EzCoder, Inc. is a Delaware corporation with its principal place of business in Texas, United States.

This Privacy Policy explains what information we collect, how we use it, who we share it with, and the choices you have. EzCoder plays two different roles with data:
  • For your own account and the projects you build, we decide how your information is handled and are responsible to you directly. Part I covers this.
  • For data about your customers and the visitors to the sites you deploy with EzCoder, we handle that data on your behalf and under your instructions. Part II covers this.
If you do not agree with this policy, please do not use EzCoder.

Part I: Your EzCoder account

The information we hold about you as an EzCoder user.

2. Information we collect

Account and profile. When you sign up, we collect your name, email address, and basic profile details. If you sign in with Google or GitHub, we receive profile information from that provider. If you connect GitHub for repository import, we store an encrypted access token.

Subscription and billing. We store your subscription plan, status, billing dates, and token or credit balances. Payments are processed by Stripe. We do not store full card numbers; we keep only limited details such as the card brand and last four digits, plus invoice and receipt records.

Prompts, conversations, and generated content. We store the messages you send to the AI assistant, its responses, and the code, files, and projects you create. Anything you paste into a prompt or file, including other people's personal information or secrets, is stored as part of your project, so please avoid sharing sensitive information you do not want retained.

Generation records (telemetry corpus). To measure and improve generation quality, we keep records of certain file-generating turns in the editor and Business Suite: the code we generated, the difference between it and what came before, and, when you later edit AI-generated files, the edited version. We scan this content for secrets and redact the credential patterns we recognize before storing it, but that scanning targets credentials, not all personal or confidential information — this content may still contain personal, proprietary, or confidential material you included, and you are responsible for what you submit. Section 4 explains how this is used and how to control any training use.

Uploads and media. We store files and assets you upload (images, documents, spreadsheets, and similar) and the inputs you provide for image, video, audio, and avatar generation. Audio from video creatives may be sent to a transcription provider to generate captions.

Business Suite content. If you use the Business Suite, we store the business data you create or import through it — including customer/CRM records, the content of email you send and receive through the built-in mailbox and its attachments, prospect/lead records (including contacts sourced from public sources at your direction), and campaign and analytics data. Much of this concerns other people and is covered by Part II.

Connected accounts. If you connect social accounts (such as X, Facebook, Instagram, or TikTok), ad platforms, or payment accounts, we store encrypted access tokens and basic account details, and we send the content you choose to publish to those platforms.

Usage and device information. We log activity in your account, including your IP address, browser and device information, pages and features used, request details, and error reports. This information is linked to your account and is not anonymous. We use it to operate, secure, and improve the service.

Information from third parties. We receive limited information from the services you connect, such as your profile from Google or GitHub at sign-in and payment events from Stripe.

3. How we use your information

We use this information to:
  • Provide, operate, and maintain the EzCoder platform
  • Authenticate you and secure your account
  • Generate, run, preview, and deploy your projects
  • Process payments and manage subscriptions
  • Provide support and send service-related communications
  • Detect and prevent fraud, abuse, and security incidents
  • Measure, debug, and improve EzCoder, including generation quality
Legal bases. Where laws such as the EU or UK GDPR apply, we process your information to perform our contract with you, for our legitimate interests in operating, measuring, and securing the service, to comply with legal obligations, and with your consent where required (including for any training use described in Section 4).

4. AI processing and improvement of your content

How generation works. EzCoder's core features are powered by AI models from third-party providers, including Anthropic, OpenAI, and Google, along with specialized providers for images, video, audio, embeddings, web search, and code search. To generate responses, your prompts, code, project content, and related inputs are sent to these providers — either directly or through our request-routing provider, OpenRouter. Code and documents are also sent to an embeddings provider (Voyage AI, or OpenAI where Voyage is not enabled) to power code search. The providers we use are listed on our Service Providers page. These providers process your content under their commercial API terms, which govern their own use and retention of it; we encourage you to review them.

Using your content to improve EzCoder. We keep the generation records described in Section 2 to evaluate and improve EzCoder's generation quality. Using this content to train or fine-tune AI models is a separate, opt-in choice:
  • Training use is off by default. We will not use your prompts, code, or edits to train models unless you turn training on in your account settings.
  • If you opt in, training use applies only going forward, to content generated after the opt-in takes effect (no earlier than 30 days after the date of this policy). Content generated before then is not used for training.
  • You can turn training off again at any time in Settings; we stop using new content for training when you do.
  • We do not use the following for training, even if you opt in: the contents of your mailbox, contacts sourced from public sources, and data about your app's end-users (none of which are part of this corpus); and, to the extent we can identify it, content of a user we know to be a minor and information we recognize as sensitive. We do not describe this content as anonymized, because we cannot guarantee it is.
Where the EU or UK GDPR applies, this training use is based on your consent, and you can withdraw it at any time.

Interacting with AI; AI-generated output. When you use EzCoder you are interacting with AI systems, and the code, text, and media EzCoder produces are AI-generated. Where the law requires AI-generated media to carry a machine-readable marking (for example under the EU AI Act as it comes into effect), we will comply with those requirements as they apply to us; this obligation does not apply to source code.

Internal access. Staff access to your project content and conversations is restricted, purpose-limited (such as support, safety, and service improvement), and logged.

Your secrets. API keys and credentials you store with us are encrypted and are injected into your running applications at runtime; they are not intentionally included in the prompts we send to AI models. Content you paste into a conversation yourself is sent as part of the prompt, so avoid pasting secrets.

5. Who we share your information with

We share information with service providers that help us run EzCoder, including cloud hosting, database, and storage providers; a content delivery, DNS, object-storage, and domain-registration provider; payment processing (Stripe); email and SMS providers; AI, embeddings, and media-generation providers; a request-routing provider; and error and operational monitoring tools. A list of the providers we use, with each provider's purpose and role, is published on our Service Providers page.

We may also disclose information to comply with law, enforce our agreements, protect the rights, safety, and security of EzCoder and others, or in connection with a corporate transaction such as a merger or acquisition.

We do not sell your personal information for money. Some privacy laws, including the California Consumer Privacy Act as amended (CCPA/CPRA), define "selling" or "sharing" broadly enough to cover certain disclosures. Where those laws apply, you can exercise your opt-out rights as described in Section 8. We honor the Global Privacy Control signal for the purposes described in our Cookie Policy.

Google user data and the Google API Services User Data Policy. When you connect a Google Ads account, we access Google user data limited to your Google Ads account identifiers and the campaign, ad, budget, and performance data for the accounts you explicitly authorize. We use this data solely to create, manage, and report on the advertising campaigns you direct from EzCoder, and we store the associated OAuth tokens encrypted at rest (AES-256-GCM); these tokens are never included in the prompts we send to AI models. EzCoder's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not sell Google user data, we do not use it to develop, improve, or train generalized AI or machine-learning models, and we do not share it with third parties except the service providers listed on our Service Providers page strictly to provide the advertising features you request. The same limitations apply to data we receive from the Meta (Facebook/Instagram) marketing platform.

6. Security

We use industry-standard safeguards to protect your information, including encryption of data in transit to and within our platform, encryption at rest for sensitive items such as access tokens and stored credentials, hashed passwords, access controls, rate limiting, audit logging, and isolation between customer projects. Some third-party data APIs that the apps you build call through EzCoder connect over the provider's own endpoint, which may not be encrypted in transit; these are listed on our Service Providers page. No method of transmission or storage is completely secure, so we cannot guarantee absolute security.

Payment card data. Card payments are processed by Stripe. EzCoder does not receive or store full card numbers.

If we become aware of a breach of security affecting your personal information, we will notify affected users without undue delay, consistent with applicable law.

7. Data retention and deletion

We retain your information while your account is active. Today, our general practice is:
  • Projects, files, and conversations: kept until you delete the project or your account (older chat messages move to long-term archive storage after about 30 days; your recent history stays available)
  • Generated media assets: retained based on your plan, from 7 days to indefinitely
  • Usage, telemetry, and security logs: retained for security, operations, and quality purposes
  • Billing records: retained as required for tax, accounting, and legal obligations
Retention we are rolling out. We are implementing shorter, enforced retention windows and will apply them as they ship: a default cap of about 30 days for verbatim chat and attachments (extendable to 90 days by opt-in), about 90 days for raw generation telemetry, about 13 months for minimized, pseudonymized quality metrics, and about 13 months for audit and security evidence. Until these are enforced, the practice above applies.

Deleting your data. You can delete individual projects at any time, and you can delete your entire account from Settings. When you delete an account, we remove your account, projects, conversations, and connected-account tokens from our active systems, and we work to remove associated data across the backends we use. Some copies persist for a limited time in archives and backups and age out on a rolling window; deletion is not instantaneous across every system. You can also email [email protected] to make a deletion request; we will process it and confirm when it is complete.

8. Your choices and rights

You can, at any time:
  • Access and update your profile in Settings
  • Export your data: a limited account export is available in Settings, and individual projects can be exported from the editor. To request a copy of your personal data under an access or portability request, email [email protected]
  • Delete individual projects or your entire account in Settings
  • Turn AI training use of your content on or off in Settings (Section 4)
  • Disconnect connected third-party accounts
  • Opt out of non-essential emails using the unsubscribe link in those emails
Depending on where you live, you may also have legal rights to access, correct, delete, or export your personal information, to object to or restrict certain processing, to withdraw consent, and to opt out of certain disclosures or of profiling. Residents of US states with comprehensive privacy laws — including California (CCPA/CPRA), Virginia, Colorado, Connecticut, Texas, Oregon, Montana, Maryland, and others — have these rights under their state laws, and residents of the EU, UK, and other regions have them under the GDPR and equivalent laws. To exercise a right, use the tools above or email [email protected]. We may need to verify your identity, and we will not discriminate against you for exercising your rights. We respond within the time your law allows (generally 45 days under US state laws and one month under the GDPR), and we may extend where permitted. If we decline a request, you may appeal by replying to our response, and you may also lodge a complaint with your data protection authority (for example, in the UK, the Information Commissioner's Office).

Do Not Track and Global Privacy Control. The EzCoder platform does not use cross-site advertising cookies and does not sell your personal information. Our own browser analytics on the platform do not currently respond to Do Not Track or an in-browser GPC signal, because that analytics does not sell data or track across sites. Sites deployed with EzCoder honor the Global Privacy Control signal in their analytics as described in our Cookie Policy.

9. Automated decisions and profiling

The Business Suite includes an optional automated assistant ("Business Brain") that can analyze your business data and propose or take marketing, outreach, content, and related actions. Sensitive or paid actions are subject to approval controls, spend and send caps, and audit logging. This automation acts on your own business data at your direction; it does not make legal or similarly significant decisions about other people on our behalf.

We do not currently use cross-customer ("fleet") learning in production; if we enable it, we will update this policy and provide an opt-out. If you are subject to a decision based solely on automated processing that produces legal or similarly significant effects on you, you have the right to obtain human review, to express your view, and to contest the decision, as provided by the GDPR and UK law.

Part II: Your customers and site visitors

Data about your end customers and your deployed sites' visitors, which we process on your behalf.

10. Data you process through EzCoder

EzCoder includes customer relationship, mailbox, marketing, analytics, advertising, and hosting features. When you use them, we handle information about your own customers, your prospects and correspondents, and the visitors and end-users of the sites and apps you deploy, on your behalf and under your instructions. This may include:
  • Customer and prospect records you create, import, or source (name, email, phone, company, tags, notes, and custom fields)
  • The content of email you send and receive through the mailbox, including attachments, and its AI classification
  • The data your deployed apps collect from their own end-users, held in the per-project database we provision for you (including any sign-in accounts your app creates)
  • Analytics from your deployed sites: page views, referrers, device and browser information, performance metrics, and errors. Visitor IP addresses are stored only in a hashed form. Visitor email addresses are not stored on analytics events; they are kept only in your customer records, under your control
  • Email and SMS campaign recipients and delivery results
  • Advertising audiences you build, which are sent to ad platforms in hashed form; and, if you set up a retargeting pixel on your own site, the audience data that pixel collects
  • Payments your customers make to you through your connected Stripe account, including the customer email and amounts, which we record to power your app and your dashboards
For this information, you are the controller and EzCoder is your service provider (processor). You are responsible for giving privacy notices to your customers and visitors, obtaining any required consent (including for cookies, analytics, and any retargeting pixel on your deployed sites), and having a lawful basis for the processing — including for any marketing or cold outreach you send, and for any contacts you source from public sources. You can turn deployed-site analytics off per project in your project settings. Our processor terms are set out in our Data Processing Addendum.

11. Visitors to sites built on EzCoder

If you are a visitor to, or an end-user of, a website or app built on EzCoder, the owner of that site is responsible for your data, and their privacy notice applies. You can still contact us at [email protected]: we will identify and forward your request to the site owner, and where the owner is unreachable or their account is closed, we will action deletion requests for the visitor data we hold ourselves. Your browser's Global Privacy Control signal is honored on deployed-site analytics: when it is on, persistent identifiers are not stored and a reduced, per-visit measurement is used.

General

12. Cookies and similar technologies

EzCoder uses cookies and browser storage to keep you signed in, secure the platform, remember preferences, and operate previews. Sites you deploy may also set cookies and browser storage for analytics, testing, and access control. For the full list and your choices, see our Cookie Policy.

13. Children's privacy

EzCoder is not intended for children under 13, and we do not knowingly collect personal information from children under 13. If you are under 18 — or under the age of majority or digital-consent age where you live — you may use EzCoder only with the involvement of a parent or guardian. We do not knowingly use the content of a user we know to be a minor to train AI models. If you believe a child has provided us personal information, contact us and we will delete it.

14. International data transfers

EzCoder is operated from the United States, primarily from Texas, and may use service providers located in other countries. If you access EzCoder from outside the United States, your information will be transferred to and processed in the United States, whose data protection laws may differ from those of your country. Where we transfer personal data subject to the EU or UK GDPR, we rely on an appropriate transfer mechanism, such as the European Commission's Standard Contractual Clauses (and the UK Addendum), or another lawful safeguard, and we make the relevant terms available on request.

15. Governing law

This Privacy Policy is governed by the laws of the State of Texas and applicable United States federal law, without regard to conflict-of-laws principles. Nothing in this section limits any rights you have under the consumer privacy laws of your place of residence.

16. Changes to this policy

We may update this Privacy Policy from time to time. Material changes apply prospectively: we will update the date above and give notice through the platform or by email at least 30 days before material changes take effect, and we will not materially expand how we use previously collected information without your consent.

17. Contact us

If you have questions about this Privacy Policy or your information, or to make a privacy request, contact us at:

EzCoder, Inc.
Email: [email protected]

We do not publish a street address. If a postal address is required for a formal legal request, we will provide one on request.