ea z z z y .ai
How it works Packages MCPs Book free call

Privacy Policy

What we collect, why, where it lives, and exactly how to delete it. No surprises.

Effective 22 June 2026 · Last updated 22 June 2026

Contents

  1. Who we are
  2. What data we collect
  3. Use of Google user data
  4. Why we collect it
  5. Sharing & sub-processors
  6. Retention & storage
  7. Your rights
  8. How to delete your data
  9. Security
  10. Children
  11. Changes to this policy
  12. Contact

1. Who we are

This Privacy Policy describes how eazzzy.ai ("eazzzy", "we", "us") handles personal information when you visit our website, book a Discovery Call, or use our hosted services — including the Google MCP server at gmcp.eazzzy.ai and any installed MCPs from our marketplace.

The data controller is the eazzzy.ai team. You can reach us at zzz@eazzzy.ai.

2. What data we collect

From the landing site (eazzzy.ai)

  • Analytics events (page views, anonymous clicks, scroll depth, session replays without input fields) via PostHog. Tied to a randomly generated ID, not your name.
  • Edge metrics (request count, country, browser) via Cloudflare. Aggregated, not tied to identity.
  • What you type into a contact form if you choose to send us one — name, email, message.

From hosted services (gmcp.eazzzy.ai and marketplace MCPs)

  • Account token we generate for you — a random 64-character string identifying your MCP install.
  • OAuth refresh & access tokens issued by Google when you connect a Google account. Stored encrypted at rest on our server.
  • Connected account email and display name (from Google userinfo).
  • Audit log — which MCP tool was called, at what time, with which argument summary (e.g. gmail_search query="from:boss"). The summary is truncated; we do not log full message bodies.

3. Use of Google user data

Limited Use compliance. eazzzy.ai's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

When you connect a Google account to gmcp.eazzzy.ai, you grant the following read and write scopes:

ScopeWhat we can doWhat we never do
gmail.readonly Search and read messages in your inbox when you (or your Claude session acting on your behalf) calls the gmail_search or gmail_read tool. We never send mail, modify labels, delete messages, or bulk-export your mailbox.
drive.file Create new files in your Drive (via drive_upload) and read back files our app has created. We cannot see, list, or open files our app did not create or that you did not explicitly pick. drive.file is a per-file scope by design.
userinfo.email, userinfo.profile Identify which Google account you connected (email + display name) so we can label it in the UI. We do not access your address book, photos, contacts, calendar, or any other Google service.

Strict Limited Use guarantees

  • We do not use Google user data to train, develop, or improve generalized AI/ML models.
  • We do not sell Google user data.
  • We do not transfer Google user data to third parties except (a) as necessary to provide the service, (b) for security and abuse prevention, or (c) to comply with applicable law.
  • We do not let humans read Google user data unless we have your explicit consent, it's required for security, or we are legally compelled.
  • The data is used only to perform the specific operation you (or your AI agent) invoked — fetching mail when you call gmail_search, uploading a file when you call drive_upload, and so on.

4. Why we collect it

  • Provide the service. We need OAuth tokens to call Google APIs on your behalf. Without them, the MCP tools can't function.
  • Operate & debug. The audit log lets us investigate failures and prevent abuse. It contains tool name, argument summary, and timestamp — not the contents fetched.
  • Improve the product. Aggregate analytics (PostHog) tell us which features people use. Identifiers are pseudonymous; we do not link them to your inbox content.
  • Comply with law. Some retention is required by tax, accounting, or fraud-prevention obligations.

5. Sharing & sub-processors

We share data only with the sub-processors we need to run the service:

Sub-processorPurposeData shared
Hetzner / Netcup (hosting)Server infrastructure for gmcp.eazzzy.aiEncrypted OAuth tokens, audit log
CloudflareDNS, TLS, CDN, DDoS protectionRequest metadata (IP, country, UA) — encrypted in transit
PostHog (US)Product analytics & session replayPseudonymous event data from the landing site
Google LLCIdentity, Gmail, Drive APIsOAuth client requests you trigger
Google WorkspaceInbound mail at zzz@eazzzy.aiEmail contents you send us

We do not sell your data. We do not use it for advertising. We do not share it with data brokers.

6. Retention & storage

  • OAuth tokens — kept until you disconnect the account or delete your eazzzy account. Stored on EU-region servers.
  • Audit log — 90 days, then rotated.
  • Analytics events — 12 months in PostHog, then rolled up to aggregates.
  • Contact-form / email correspondence — 24 months after the last reply, then deleted.

7. Your rights

Depending on where you live (GDPR / UK GDPR / CCPA / Brazilian LGPD), you may have the right to:

  • Access the personal data we hold about you.
  • Correct it if it's wrong.
  • Delete it (right to erasure).
  • Export it in a portable format.
  • Object to or restrict processing.
  • Withdraw consent at any time without affecting the lawfulness of past processing.
  • Lodge a complaint with your local data-protection authority.

Email zzz@eazzzy.ai with the subject line "Privacy request" — we respond within 30 days.

8. How to delete your data

You have two independent ways to remove your Google account from eazzzy:

  1. Revoke directly at Google. Go to myaccount.google.com/permissions → find "eazzzy.ai (gmcp)" → Remove access. This instantly invalidates the OAuth tokens we hold. Google notifies our server and we delete the stored tokens within 24 hours.
  2. Email us at zzz@eazzzy.ai. We will delete your account, tokens, and audit log within 7 days and confirm in writing.

After deletion, anonymized aggregate analytics may persist (we can't tie them back to you).

9. Security

  • TLS 1.2+ everywhere; HSTS enabled.
  • OAuth tokens encrypted at rest using AES-256 (encryption key held in Infisical, separate from application code).
  • Servers behind UFW + fail2ban; SSH key auth only; no public Docker ports.
  • Principle of least scope: we ask Google for the minimum scopes that make the tools work (no full Gmail access, no full Drive access — see §3).
  • No third-party tracking pixels on logged-in pages.

We're a small team. If you find a security issue, please email zzz@eazzzy.ai with "Security" in the subject. We'll acknowledge within 48 hours.

10. Children

eazzzy.ai is a B2B tool for small businesses and not directed at anyone under 16. We do not knowingly collect data from minors.

11. Changes to this policy

If we make a material change (new scope, new sub-processor, change of legal basis), we'll update the "Last updated" date and email everyone with a connected account at least 14 days before the change takes effect.

12. Contact

eazzzy.ai
Email: zzz@eazzzy.ai
Privacy requests: zzz@eazzzy.ai (subject: "Privacy request")
Security disclosures: zzz@eazzzy.ai (subject: "Security")

© 2026 eazzzy.ai · AI automation done for you.
Home Terms Privacy Contact