Legal
Privacy Policy
Last updated: September 2026
1. Scope
This Privacy Policy explains what information EzAI (“EzAI”, “we”, “us”) collects, how we use it, and the choices you have. It applies to the EzAI website, apps, and APIs (the “Service”).
2. What we collect
Account data: if you sign in, your email address and any profile fields you choose to add (name, country, preferred language).
Content: the prompts you submit and the responses generated for you. Chat history, saved tools, the Context Vault, and the Academic Library are stored locally in your browser by default, and — only where you are signed in and have enabled sync — in our database under Row Level Security so that only your account can read them.
Usage data: coarse technical logs (timestamps, request counts, IP address, error traces, rate-limit counters) used to operate and secure the Service.
Voice input: audio you record for voice-to-text is streamed to a transcription provider and is not retained by EzAI after the transcript is returned.
3. Zero training on your content
EzAI does not train, fine-tune, or otherwise build machine-learning models on your prompts, your responses, your uploaded files, your voice recordings, or your Academic Library.
All model inference runs through third-party providers’ commercial APIs (for example OpenAI, Anthropic, and Google). We only use providers whose API terms contractually state that data submitted via the API is not used to train or improve their foundation models, and is retained by them only transiently for abuse monitoring before deletion.
We do not sell your content, and we do not share it with advertisers.
4. Academic Workspace data isolation
When the Academic Workspace is active, queries are handled in an isolated research context: the prompt and the retrieved sources for that query are processed only to produce the cited answer and are not blended into your general chat memory or used to personalise unrelated results.
Items you explicitly bookmark to the Academic Library are stored under your account (or locally, if you are not signed in) with their auto-generated topic tags. They are never shared with other users and are not used for training.
Academic research queries are subject to a daily fair-use quota; the counter records only the number of queries and their reset time, not their contents.
5. How we use information
To provide the Service: route your request to the right model, return and store your results, and remember your preferences.
To keep the Service safe and reliable: enforce rate limits, detect abuse and fraud, debug errors, and monitor capacity.
To communicate with you about security, changes to the Service, or support requests.
We rely on your consent (for optional profile data and sync), on performance of our contract with you (to run the Service), and on our legitimate interests (security and improvement of the product itself, not of third-party models).
6. Sharing
We share information only with: (a) infrastructure and model-API providers that process data on our instructions to run the Service; (b) authorities where required by valid legal process; and (c) a successor entity in a merger or acquisition, subject to this Policy.
Each processor is bound by contractual confidentiality and data-protection obligations.
7. Retention
Content you store locally stays until you clear it from your browser. Content synced to your account is retained until you delete it or close your account, after which it is removed from active systems within 30 days (backups cycle out on a rolling 90-day basis).
Security logs are kept for a limited period proportionate to their purpose and then deleted or aggregated.
8. Your rights
Depending on your location, you may have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing. You can exercise most of these directly in the product (profile settings, chat history controls, “Clear All Chats”, and the Academic Library). For anything else, contact us.
You can withdraw consent for optional data at any time without affecting prior processing.
9. Security
API keys and provider credentials are held only on the server and are never exposed to the browser. All model and research calls run through server-side routes with origin checks and rate limiting. Transport is encrypted with TLS. Database access is gated by Row Level Security tied to your authenticated identity.
10. International transfers & children
Your data may be processed in countries other than your own, including where our providers operate. Where required, we use appropriate safeguards such as standard contractual clauses.
The Service is not directed to children under 16, and we do not knowingly collect their personal data.
11. Changes & contact
We may update this Policy; material changes will be reflected in the date below and, where appropriate, announced in the product.
For privacy questions or requests, contact the EzAI team through the support channel listed in the app.
