Privacy & cookies

Last updated 1 July 2026.

This covers ezyapp.com itself — the marketing site, your account, and the app admin. Apps built on EzyApp are run by their own owners; see generated apps below.

The short version

Cookies we set

One first-party session cookie, better-auth.session_token, issued by our authentication system once you sign in. EzyApp runs three separate sign-in systems for three separate groups of people, so the cookie's lifetime depends on where you signed in:

Platform console · ezyapp.com
Keeps you signed in to your EzyApp account. Expires after 7 days.
App admin · <app>.ezyapp.com/_admin
Keeps app staff signed in while authoring an app. Expires after 14 days.
Published app · <app>.ezyapp.com
Keeps a published app's own customers signed in. Expires after 30 days.

Every one is host-only (never shared across subdomains), HttpOnly (not readable by JavaScript), Secure (sent only over HTTPS), and SameSite=Lax (a cross-site request-forgery defence). A signed-in session on one app is not a session on any other app, or on your account.

Infrastructure cookies

Our host, Cloudflare, may set a small number of strictly-necessary infrastructure cookies — for example __cf_bm (bot management), __cflb (load balancing), and cf_clearance (security challenges). These keep the service available and secure; we do not control or read them, and they do not track you across other sites.

What we don't do

We don't set advertising or marketing cookies, we don't profile you across other websites, and we don't sell or share your personal information. If we add product analytics later, it will be configured to store nothing on your device — so this stays banner-free.

Information we collect

The playground & the onboarding chat

The playground and the onboarding chat on our home page let you try the AI app builder without an account. During our beta we keep a transcript of each chat — your messages, the assistant's replies, and the changes it made — so we can see where the AI helps and where it falls short and improve it. There is no account attached. We do not store your IP address; we keep only a one-way keyed hash of it, used to spot abuse. Transcripts are kept for up to 30 days and then deleted. This capture happens on our servers and stores nothing on your device. The app you build is still ephemeral — it disappears when the 7-day session ends.

One thing to note about the onboarding chat: to build you a starting site it asks about your business, so anything you choose to share there — a business name, email, phone number or address — is part of that transcript. It's only used to build your preview and to improve the assistant, it isn't published anywhere, and it's deleted on the same 30-day schedule. Please don't enter details you'd rather we didn't keep.

The app admin

When you build or edit an app in the admin with the AI assistant, we keep a transcript of that authoring chat — your messages, the assistant's replies, and the changes it made — so we can see where the AI helps and where it falls short and improve it. Unlike the playground, this happens inside your signed-in account and is attached to the app you're building, so we don't store any IP address for it. These transcripts are kept for up to 30 days and then deleted, are visible only to our operators, and are never published.

Apps built on EzyApp

An app published on EzyApp (at <app>.ezyapp.com or a custom domain) is operated by its own owner. That owner is the data controller for their site and its visitors and is responsible for their own privacy notice; EzyApp provides the hosting infrastructure. This policy covers ezyapp.com itself, not the apps built with it.

Contact

Questions about privacy? Email want@ezyapp.com.

← Back to ezyapp.com