Privacy Policy

Last updated: 4 August 2026

This policy explains what EasyWeb.AI collects when you use the service, why, who else can see it, and what control you have. The most important part is section 3: this service holds a GitHub access token on your behalf, and you should understand exactly what that means before connecting one.

1. Who is responsible

EasyWeb.AI operates this service and is the data controller for it. For any question or request about your data, use the address on our contact page.

2. Where your data is stored

The service is self-hosted on privately operated hardware rather than a commercial cloud platform. Your account, your grants and your encrypted token are stored on infrastructure we own and physically control.

Traffic reaches us through Cloudflare’s network, so requests may transit servers outside your country. Your repository contents remain on GitHub; we do not copy or retain them.

3. Your GitHub token

This is the heart of the service, so we want to be exact about it.

  • You supply a classic GitHub personal access token. It is encrypted before storage, using a key derived from this installation’s secrets.
  • It is never displayed in the interface, never sent to a browser, and never shown to anyone you grant access to — including administrators of this service in normal operation.
  • It is decrypted only in memory, at the moment a request is made to GitHub on your behalf.
  • The token acts with whatever permissions you gave it on GitHub. We can restrict which repositories a given person may reach through this service, but we cannot reduce the token’s own scope. Issue a token scoped to only what you need.
  • You can remove the token at any time, which immediately ends the service’s ability to act on your GitHub account. Revoking it on GitHub achieves the same thing.

4. What else we collect

Account information

Your username, email address, and password — the last stored only as a cryptographic hash, never in readable form.

Access grants

A record of which people may reach which repositories. If someone grants you access, the owner can see that you hold it.

Connection credentials

If you connect Claude Desktop or a custom GPT, we store the credentials that link them to your account — personal connection keys and OAuth tokens. These are stored hashed or encrypted and can be revoked individually.

Repository content in transit

When you browse or edit a file, its contents pass through the service to reach you. We do not store a copy. What you commit is written to GitHub and lives there under your own history.

Technical logs

Our servers and Cloudflare record IP addresses, timestamps, requested URLs and user agents, used to keep the service running and to detect abuse.

Your optional site

Registering also creates a site on a subdomain. Anything you publish there is stored by us and is public unless you set it otherwise.

What we do not do

  • We do not sell or rent your personal information.
  • We do not share it with advertising networks or data brokers.
  • We do not run behavioural advertising or cross-site tracking.
  • We do not use your repository contents to train machine learning models.

5. Why we collect it

PurposeData usedLegal basis (GDPR)
Running your accountAccount informationPerformance of a contract
Acting on GitHub as you askedEncrypted token, access grantsPerformance of a contract
Connecting Claude Desktop or a custom GPTConnection keys, OAuth tokensPerformance of a contract
Service email such as activation and password resetEmail addressPerformance of a contract
Preventing abuse and automated attacksIP address, user agent, bot signalsLegitimate interests
Keeping the service available and secureTechnical logs, backupsLegitimate interests

6. Who else can see your data

A small number of third parties are involved in running the service. The full list, with what each receives, is on our subprocessors page. In summary: GitHub (the repositories themselves), Cloudflare (traffic delivery and bot protection), Mailgun (service email), Automattic (profile images, where enabled), and WordPress.org (software updates).

We may also disclose data where legally required, or where necessary to protect the safety and integrity of the service.

7. How long we keep it

  • Account data, tokens and grants — for as long as your account exists. Closing your account deletes them.
  • Technical logs — kept short term for operations and abuse detection, then discarded.
  • Backups — data you delete may persist in backups until those rotate out.

8. Your rights

Wherever you live, you can ask for a copy of your data, ask us to correct it, or ask us to delete it. Contact us and we will respond within 30 days. We may need to verify your identity first.

If you are in the EU or UK (GDPR)

You have rights of access, rectification, erasure, restriction, portability, and objection to processing based on legitimate interests. Where we rely on consent you may withdraw it at any time. You may also complain to your national supervisory authority.

If you are in Malaysia or Singapore (PDPA)

You may request access to and correction of your data, withdraw consent to its collection, use or disclosure, and limit its processing. Withdrawing consent may mean parts of the service can no longer be provided.

If you are in California (CCPA/CPRA)

You have the right to know what is collected and why, to request deletion or correction, and not to be discriminated against for exercising those rights. We do not sell or share your personal information as those terms are defined there, and have not done so in the preceding twelve months.

9. Security, stated honestly

Connections are encrypted with HTTPS throughout. Passwords are hashed. Your GitHub token is encrypted at rest and never leaves the server in readable form. Access to repositories is granted per person and per repository, and can be revoked instantly.

We also want to be straightforward: this is a self-hosted service, currently in beta, run on private infrastructure — not an enterprise platform with a dedicated security team, formal certifications or guaranteed uptime. It holds a credential to your GitHub account, so weigh that honestly. Issue a token scoped only to the repositories you intend to manage, rather than one with access to everything.

If we discover a breach affecting your personal data — and particularly one affecting stored tokens — we will notify you promptly, and the relevant authority where the law requires it, within 72 hours under GDPR.

10. Children

This service is not intended for children under 16 and we do not knowingly collect their data.

11. Changes

We may update this policy as the service changes. The date at the top shows the current version. Where a change materially affects your rights, registered users will be told by email before it takes effect.

12. Contact

Questions, requests or complaints: see our contact page.