Security & data protection
Uploading a revenue spreadsheet takes trust. Here is exactly how we handle, store, and protect your data — and what we deliberately don't do with it.
Where your data lives
Eazy runs entirely on Cloudflare. Your uploaded files, generated decks, and account data are stored on Cloudflare's infrastructure (R2, D1, KV, Vectorize, Images, and Durable Objects), encrypted at rest (AES-256) and in transit (HTTPS/TLS) by default.
Uploaded documents are access-controlled — served only to their owner through an authenticated request, never from a public URL.
Your content is never used to train AI
To generate and edit your slides, your content is processed by Google Gemini, Anthropic Claude, and Cloudflare Workers AI. We use these under paid/commercial terms that prohibit training on your data — your prompts and documents are never used to train any AI model. Providers retain API data only briefly for abuse monitoring (typically up to 30 days), then delete it.
Access & sign-in
Sign-in is handled by Google OAuth 2.0 — we never see or store your Google password. Access to your documents, images, and presentations is scoped to your account.
Who processes your data (sub-processors)
The services that help us run Eazy, and what each handles:
- Cloudflare — hosting, storage, images, and AI processing
- Google (Gemini) & Anthropic (Claude) — presentation generation and editing
- fal.ai — AI image generation
- Unsplash — stock image search
- Resend — account and transactional email
- Polar — payments and credits (card details are handled by Polar; we never store them)
- PostHog — product analytics (AI prompt and response content is redacted)
Delete anytime
You can delete any document, image, or presentation from within the app at any time — it is removed from storage, the database, embeddings, and live editing state.
You can also delete your entire account and all associated data from your account settings. On deletion, your content is erased from our active systems, except where limited retention is required by law or to prevent abuse.
What we don't do
- We don't sell your personal information.
- We don't use your content to train AI models.
- We don't expose your uploaded documents on public URLs.
A note on certifications
We're an early-stage product and don't yet hold formal certifications such as SOC 2 or ISO 27001. Rather than claim a badge we haven't earned, we've focused on getting the fundamentals right and documenting them transparently here. We'll pursue formal certification as we grow and our customers need it.
Questions or a security concern?
For privacy questions or to report a potential vulnerability, email us at support@eazyhq.com. We appreciate responsible disclosure. See also our Privacy Policy.