Privacy Policy
What leaves your browser, who receives it, and how to get it back or get rid of it.
Last updated 7 September 2026
The short version
What we collect
- Account — your email, and a display name and avatar if you set one or sign in with a provider that supplies them.
- Your work — project names, the files in each project, chat history, and version snapshots.
- Usage — the token count of each generation, which is what your credit balance is metered from, plus which model was used.
- Billing — what you bought, when, the amount, and the payment's status and identifiers from our processor.
- Settings — reasoning effort, theme, voice and editor options.
We do not run third-party advertising or analytics trackers, and we do not build a profile of you across other sites.
Prompts & generated code
For each AI-generated change, your prompt, relevant conversation, enabled instructions, attachments and project files are processed by OpenAI to draft the change. A separate Astra pass receives the context and draft to review and revise it before Webzy applies the result. This sequence applies to every project and cannot be disabled for generation. Manual file edits do not trigger this generation sequence by themselves.
When a build requests a generated 3D asset, its description is sent to Tripo. When image generation is available and used, the image description is sent to Black Forest Labs. These services return the generated assets for the project.
Webzy does not use your prompts or generated code to train models. OpenAI processes this content through its commercial API under its applicable data policies. Background responses are stored so work can resume across worker restarts. Provider retention and abuse monitoring can still apply; Webzy does not promise zero retention at the provider. AI review can miss defects and is not a guarantee of secure or error-free code.
If a project contains something you would not want a third party to process, do not put it in a prompt or a project file. Use a connector or an environment variable in your deployed site instead.
Payment data
There are two ways to pay, and neither of them puts your payment details in front of us. Card payments are taken by Paddle, who are the merchant of record — the sale is legally theirs, they host the checkout, and they handle sales tax and VAT. Cryptocurrency payments are taken by NOWPayments, who host their own checkout page.
We never receive card details, bank details, or your wallet's private keys. Those are entered on the payment company's page, not on ours, and are never sent to Webzy.
What we store is the order: what you bought, the price in US dollars, how you paid — the coin for a crypto payment, or the card brand and last four digits for a card — and the payment company's identifiers for the invoice and transaction. That is what your billing page shows you, and what we need to answer a dispute.
Connector credentials
When you connect GitHub, Vercel, Supabase or another service, the token you provide is encrypted with AES-256-GCM before it is stored, and the column holding it is unreadable by the browser role — only server-side code holding the service key can decrypt it.
Credentials are used only to perform the action you asked for, such as a deploy. Disconnecting a connector deletes them.
Who else sees it
We use these companies to run Webzy. Each receives only what it needs.
- Supabase — database, authentication and file storage. Holds your account, projects and chat history. Hosted in the EU.
- Vercel — hosts the application and the sites you publish. Processes project files for deployment and request metadata such as IP address and user agent.
- OpenAI — drafts, reviews and revises changes using prompts, project files and conversation context. Also analyzes project questions and plans 3D asset requests.
- Tripo — generates 3D models. Sees the description of the asset being made, and nothing else unless included in that description.
- Black Forest Labs — generates images when that feature is used. Receives the image description and generation options.
- Paddle — takes card payment as merchant of record. Sees your email, your billing country and the card details you enter on their checkout, and handles the tax on the sale. We receive the order and the last four digits, never the card number.
- NOWPayments — takes cryptocurrency payment. Sees the amount and the wallet transaction; sees your email only if you enter it on their checkout.
- Upstash — optional cache for account credit balances and temporary integration data, including GitHub installation tokens when that cache is enabled.
Optional dictation uses your browser's speech recognition service. Depending on the browser, audio may be processed by its speech provider. Webzy receives the resulting text for your prompt.
We may also disclose data where the law requires it. We will tell you if that happens unless we are legally prevented from doing so.
How long we keep it
- Account and projects: until you delete them, or delete your account.
- Chat history and version snapshots: for the life of the project.
- Billing records: kept after account deletion where tax and accounting law requires it, typically several years, and reduced to the transaction record alone.
- Server logs: a short rolling window, then discarded.
Deleting a project deletes its files, messages and snapshots. Deleting your account removes your profile, projects, settings and connector credentials.
Copies already sent to connected services, hosting providers or model providers are subject to their retention and deletion processes. Removing a project record does not by itself remove every external copy.
Your rights
Depending on where you live you may have the right to access a copy of your data, correct it, delete it, restrict or object to processing, and receive it in a portable form. We honour these requests regardless of where you are.
Source-code downloads from the editor require Pro or higher. Projects can be deleted in settings. These plan limits do not restrict your data rights. To request account deletion or exercise other data rights, email legal@webzy.online and we will respond within 30 days.
Where data lives
Your account and projects are stored in the European Union. The application is served from a global edge network, and the model providers process prompts in the United States. Transfers outside the EU rely on the standard contractual clauses those providers offer.
Contact
Privacy questions and data requests go to legal@webzy.online. Product questions go to hello@webzy.online.