Contents
1. Who we are
This Privacy Policy describes how eazzzy.ai ("eazzzy", "we", "us") handles personal information when you visit our website, book a Discovery Call, or use our hosted services — including the Google MCP server at gmcp.eazzzy.ai and any installed MCPs from our marketplace.
The data controller is the eazzzy.ai team. You can reach us at zzz@eazzzy.ai.
2. What data we collect
From the landing site (eazzzy.ai)
- Analytics events (page views, anonymous clicks, scroll depth, session replays without input fields) via PostHog. Tied to a randomly generated ID, not your name.
- Edge metrics (request count, country, browser) via Cloudflare. Aggregated, not tied to identity.
- What you type into a contact form if you choose to send us one — name, email, message.
From hosted services (gmcp.eazzzy.ai and marketplace MCPs)
- Account token we generate for you — a random 64-character string identifying your MCP install.
- OAuth refresh & access tokens issued by Google when you connect a Google account. Stored encrypted at rest on our server.
- Connected account email and display name (from Google userinfo).
- Audit log — which MCP tool was called, at what time, with which argument summary (e.g.
gmail_search query="from:boss"). The summary is truncated; we do not log full message bodies.
3. Use of Google user data
When you connect a Google account to gmcp.eazzzy.ai, you grant the following read and write scopes:
| Scope | What we can do | What we never do |
|---|---|---|
gmail.readonly |
Search and read messages in your inbox when you (or your Claude session acting on your behalf) calls the gmail_search or gmail_read tool. |
We never send mail, modify labels, delete messages, or bulk-export your mailbox. |
drive.file |
Create new files in your Drive (via drive_upload) and read back files our app has created. |
We cannot see, list, or open files our app did not create or that you did not explicitly pick. drive.file is a per-file scope by design. |
userinfo.email, userinfo.profile |
Identify which Google account you connected (email + display name) so we can label it in the UI. | We do not access your address book, photos, contacts, calendar, or any other Google service. |
Strict Limited Use guarantees
- We do not use Google user data to train, develop, or improve generalized AI/ML models.
- We do not sell Google user data.
- We do not transfer Google user data to third parties except (a) as necessary to provide the service, (b) for security and abuse prevention, or (c) to comply with applicable law.
- We do not let humans read Google user data unless we have your explicit consent, it's required for security, or we are legally compelled.
- The data is used only to perform the specific operation you (or your AI agent) invoked — fetching mail when you call
gmail_search, uploading a file when you calldrive_upload, and so on.
4. Why we collect it
- Provide the service. We need OAuth tokens to call Google APIs on your behalf. Without them, the MCP tools can't function.
- Operate & debug. The audit log lets us investigate failures and prevent abuse. It contains tool name, argument summary, and timestamp — not the contents fetched.
- Improve the product. Aggregate analytics (PostHog) tell us which features people use. Identifiers are pseudonymous; we do not link them to your inbox content.
- Comply with law. Some retention is required by tax, accounting, or fraud-prevention obligations.
5. Sharing & sub-processors
We share data only with the sub-processors we need to run the service:
| Sub-processor | Purpose | Data shared |
|---|---|---|
| Hetzner / Netcup (hosting) | Server infrastructure for gmcp.eazzzy.ai | Encrypted OAuth tokens, audit log |
| Cloudflare | DNS, TLS, CDN, DDoS protection | Request metadata (IP, country, UA) — encrypted in transit |
| PostHog (US) | Product analytics & session replay | Pseudonymous event data from the landing site |
| Google LLC | Identity, Gmail, Drive APIs | OAuth client requests you trigger |
| Google Workspace | Inbound mail at zzz@eazzzy.ai | Email contents you send us |
We do not sell your data. We do not use it for advertising. We do not share it with data brokers.
6. Retention & storage
- OAuth tokens — kept until you disconnect the account or delete your eazzzy account. Stored on EU-region servers.
- Audit log — 90 days, then rotated.
- Analytics events — 12 months in PostHog, then rolled up to aggregates.
- Contact-form / email correspondence — 24 months after the last reply, then deleted.
7. Your rights
Depending on where you live (GDPR / UK GDPR / CCPA / Brazilian LGPD), you may have the right to:
- Access the personal data we hold about you.
- Correct it if it's wrong.
- Delete it (right to erasure).
- Export it in a portable format.
- Object to or restrict processing.
- Withdraw consent at any time without affecting the lawfulness of past processing.
- Lodge a complaint with your local data-protection authority.
Email zzz@eazzzy.ai with the subject line "Privacy request" — we respond within 30 days.
8. How to delete your data
You have two independent ways to remove your Google account from eazzzy:
- Revoke directly at Google. Go to myaccount.google.com/permissions → find "eazzzy.ai (gmcp)" → Remove access. This instantly invalidates the OAuth tokens we hold. Google notifies our server and we delete the stored tokens within 24 hours.
- Email us at zzz@eazzzy.ai. We will delete your account, tokens, and audit log within 7 days and confirm in writing.
After deletion, anonymized aggregate analytics may persist (we can't tie them back to you).
9. Security
- TLS 1.2+ everywhere; HSTS enabled.
- OAuth tokens encrypted at rest using AES-256 (encryption key held in Infisical, separate from application code).
- Servers behind UFW + fail2ban; SSH key auth only; no public Docker ports.
- Principle of least scope: we ask Google for the minimum scopes that make the tools work (no full Gmail access, no full Drive access — see §3).
- No third-party tracking pixels on logged-in pages.
We're a small team. If you find a security issue, please email zzz@eazzzy.ai with "Security" in the subject. We'll acknowledge within 48 hours.
10. Children
eazzzy.ai is a B2B tool for small businesses and not directed at anyone under 16. We do not knowingly collect data from minors.
11. Changes to this policy
If we make a material change (new scope, new sub-processor, change of legal basis), we'll update the "Last updated" date and email everyone with a connected account at least 14 days before the change takes effect.
12. Contact
eazzzy.ai
Email: zzz@eazzzy.ai
Privacy requests: zzz@eazzzy.ai (subject: "Privacy request")
Security disclosures: zzz@eazzzy.ai (subject: "Security")