ezflows

Privacy policy

Last updated 14 September 2026Effective 19 August 2026

In short

  • We collect your Google account email and name, and the prompts and files you send to a model.
  • Generated files are served from public URLs. Anyone with the link can open them.
  • Generated files are deleted automatically after 90 days.
  • Your prompts are sent to the model provider you chose. They are not used to train our models.
  • You can delete your generation content at any time, and your account on request.

1. Who we are

ezflows is the data controller for the information described in this policy. For privacy questions or requests, write to developer@ezflows.io.

We decide what is collected and why. The companies listed in section 6 process information on our instructions.

2. What we collect

Account information

When you sign in with Google we receive your email address, display name and profile picture URL — nothing more, and only what Google shows you on the consent screen. We do not receive or store a password, because we never ask for one.

Google user data

We use Google only to let you create and access your ezflowsaccount. We request the openid, email and profile scopes. These give us your Google account identifier, email address, display name and profile picture URL. We do not request access to Gmail, Google Drive, Google Calendar, your contacts, or other Google account content.

  • How we access it: you choose “Continue with Google” and authorize Google to send the basic identity information listed above to our authentication provider, Supabase.
  • How we use it: to authenticate you, create your workspace, identify your account, display your name and profile picture, and send necessary account or service messages.
  • How we store it: your Google account identifier, email, display name and profile picture URL are stored in our Supabase account records while your account is active. Authentication sessions are stored in your browser so you can remain signed in.
  • How we share it: Supabase processes this information to provide authentication and account storage. We do not send Google identity data to model providers, sell it, use it for advertising, or use it to train AI models.
  • How to remove it: you can revoke ezflows's Google access from your Google Account permissions and request deletion of your ezflows account and stored profile data by emailing developer@ezflows.io. Revoking access stops future Google sign-in but does not by itself delete the account data already stored by ezflows.

What you send to a model

Prompts, parameters and any files you upload, together with whatever the model returns. We keep these so you can find your work again in your request history, and so that we can answer you when a generation goes wrong.

Usage and technical data

Which model you ran, when, how long it took, whether it succeeded, what it cost, and whether it was run from the web app or an API key. IP addresses and standard request logs are processed by our infrastructure providers for security and abuse prevention.

We do not run advertising trackers, and we do not sell or share personal data for advertising.

3. Generated files are public by URL

Read this one. Files you generate are served from media.ezflows.io at an unauthenticated URL. The address contains random identifiers and is not listed or searchable, but it is not protected by your login: anyone you give the link to, or who otherwise obtains it, can open the file until it is deleted.

This is a deliberate design choice, so that output can be embedded and shared the way other generation platforms work. Do not generate anything you would not be willing to hand to a stranger who found the link.

4. Why we process it, and on what basis

  • To provide the service — running your generations, keeping your history, metering your balance. This is performance of our contract with you.
  • To keep the service working and safe — rate limiting, abuse prevention, debugging. Our legitimate interest in operating a service that is not being abused.
  • To bill you — where a payment provider is involved, to comply with tax and accounting law.
  • To contact you about your account — service messages, not marketing. We will ask separately before sending you anything promotional.

We do not use your prompts or outputs to train models. We are not a model developer. Whether a model provider does so is governed by their terms — see section 6.

5. How long we keep it

WhatKept forWhy
Generated files90 days, then deleted automaticallyEnforced by a storage lifecycle rule, not by a script that might not run
Prompts and parametersUntil you delete them, or the account closesSo your history is useful. Purge them any time — see below
Request records (timing, cost, status)Retained after content is purgedBilling accuracy and dispute resolution. Contains no prompt or output
Credit ledgerRetained for the statutory accounting periodIt is a financial record; it is append-only by design
Account recordUntil you ask us to delete itSee section 7

Deleting a request's content is honest about what survives. It removes the prompt, the parameters and the output. It deliberately keeps the timing, cost and status, so your usage and invoices still add up. We tell you this in the app at the moment you do it, rather than in a footnote here.

6. Who else processes your data

We run on infrastructure operated by other companies. Each one processes only what it needs, and under contract.

ProviderWhat forWhat they seeWhere
SupabaseAccount records, generation metadata, credit ledger, authenticationEmail, display name, avatar URL, generation historyAWS ap-northeast-2 (Seoul, South Korea)
CloudflareAPI compute, generated file storage, DNS and CDNGenerated outputs, request logs, IP addressesGlobal edge; object storage in APAC
VercelHosting for the marketing and documentation siteIP addresses and request logs for www.ezflows.io onlyGlobal edge
UpstashPer-account concurrency countersAccount identifier and an in-flight request count. No content.Single region
GoogleSign-in (OAuth)Email, name and profile picture, only what you approve at sign-inGlobal
Model providersRunning the generation you request⚠️ The prompt and any input files for that generationVaries by provider — named on each model's page

Model providers are the ones to pay attention to. Running a generation means sending your prompt and any input files to the provider that hosts that model. Each model page names its provider before you run anything. Their handling of that data is governed by their own terms, which we cannot override on your behalf.

7. International transfers

Our database is hosted in South Korea and our storage and compute are distributed globally. Model providers may process your prompt in other countries. Where data leaves a jurisdiction that restricts transfers, we rely on the standard contractual protections our providers offer.

8. Your rights

You can ask us to:

  • Show you what we hold. Most of it is already visible in the app — your request history, usage and account settings.
  • Correct it if it is wrong.
  • Delete it. You can purge generation content yourself at any time. Account deletion is handled as a support request — deliberately, because it is irreversible and interacts with billing records we may be required to keep.
  • Export it in a portable format.
  • Object to or restrict processing based on legitimate interests.

Write to developer@ezflows.io. We will respond within 30 days. If you are in the UK or EU you may complain to your local supervisory authority.

If you are in India, you may also raise a grievance by writing to developer@ezflows.io and, where applicable, complain to the Data Protection Board of India.

9. Security

Every record belonging to your account is isolated at the database level by row-level security, not only by application code — so a bug in a page cannot expose another customer's data. API keys are stored only as hashes; we cannot show you a key again after it is created, which is why we say so at the moment we show it. Traffic is encrypted in transit.

No system is perfectly secure. If you find a vulnerability, please write to developer@ezflows.io before disclosing it publicly, and we will work with you.

10. Cookies

We use storage in your browser to keep you signed in. That is all it is for. We do not use advertising cookies or third-party trackers, which is why you are not being asked to dismiss a consent banner.

11. Children

ezflows is not for anyone under 18. We do not knowingly collect data from children. If you believe a child has an account, tell us and we will remove it.

12. Changes

We will update this page when what we do changes — including when we add a sub-processor. For anything that materially affects you, we will email account holders before it takes effect rather than quietly changing the date at the top.