Security

Your projects are yours alone

Separation is enforced beneath the application, connected accounts are protected after storage, and we explain which providers process your source during drafting and review.

Separated at the data, not in the page

Project data uses owner-scoped access policies in the database. Server operations also require identity and ownership checks. These controls work together to restrict access to your account's projects.

Credentials that cannot be read back

Anything you connect — a payment account, a mailing list, a repository — is encrypted before it is stored. Once written it cannot be read back out: not by your browser, not by anyone signed in, not by your own account. It is unlocked only on our servers, only at the moment it is actually being used.

Nothing touches your database without you

If an app needs to remember things, that data lives in a database on your own account. Webzy shows you what it wants to change, in plain words, and waits. Anything that could lose data is asked about separately every time, whatever you have already allowed, and every permission can be withdrawn.

Editing tools stay out of published code

The preview includes a bridge for selecting and editing elements. That editing bridge is removed from exported and published projects. Generated code still needs testing before you put it in front of users.

Where your source actually goes

Every AI-generated change goes through OpenAI’s Astra for drafting, then a separate review and revision pass before Webzy applies it. OpenAI receives project context and the draft. Files are also processed by our hosting and storage providers. A secret in a prompt or source file can travel with that content, so keep credentials in connectors or environment settings. Review can miss defects and does not guarantee secure code.

No trackers

Webzy does not sell your data, run third-party advertising trackers, or use your prompts and generated code to train models. Authentication and payment services process data needed to provide their features. Model-provider retention and abuse monitoring policies still apply, as described in our Privacy Policy.

Publishing is public, on purpose

Publishing puts your app at an address anyone can open. Project management requires your account. Treat any preview link you share as granting access to its contents, and keep sensitive information out of public builds.

Deleting a project

Deleting a project removes its saved files, conversation, checkpoints and deployment records from Webzy. Export anything you want to keep first. Published deployments and copies already sent to third-party services have their own deletion and retention processes.

Reporting a vulnerability

No system is perfect. If you find a vulnerability, please report it rather than exercising it, and give us a reasonable chance to fix it before disclosing. Write to legal@webzy.online.

The binding documents are the Privacy Policy and Terms of Service. Where this page and those disagree, those win.

Security · Webzy