Security
Your projects are yours alone
Separation is enforced beneath the application, connected accounts are protected after storage, and we explain which providers process your source during drafting and review.
Separated at the data, not in the page
Project data uses owner-scoped access policies in the database. Server operations also require identity and ownership checks. These controls work together to restrict access to your account's projects.
Credentials that cannot be read back
Anything you connect — a payment account, a mailing list, a repository — is encrypted before it is stored. Once written it cannot be read back out: not by your browser, not by anyone signed in, not by your own account. It is unlocked only on our servers, only at the moment it is actually being used.
Nothing touches your database without you
If an app needs to remember things, that data lives in a database on your own account. Webzy shows you what it wants to change, in plain words, and waits. Anything that could lose data is asked about separately every time, whatever you have already allowed, and every permission can be withdrawn.
Editing tools stay out of published code
The preview includes a bridge for selecting and editing elements. That editing bridge is removed from exported and published projects. Generated code still needs testing before you put it in front of users.
Where your source actually goes
Every AI-generated change goes through OpenAI’s Astra for drafting, then a separate review and revision pass before Webzy applies it. OpenAI receives project context and the draft. Files are also processed by our hosting and storage providers. A secret in a prompt or source file can travel with that content, so keep credentials in connectors or environment settings. Review can miss defects and does not guarantee secure code.
No trackers
Webzy does not sell your data, run third-party advertising trackers, or use your prompts and generated code to train models. Authentication and payment services process data needed to provide their features. Model-provider retention and abuse monitoring policies still apply, as described in our Privacy Policy.
Publishing is public, on purpose
Publishing puts your app at an address anyone can open. Project management requires your account. Treat any preview link you share as granting access to its contents, and keep sensitive information out of public builds.
Deleting a project
Deleting a project removes its saved files, conversation, checkpoints and deployment records from Webzy. Export anything you want to keep first. Published deployments and copies already sent to third-party services have their own deletion and retention processes.
Reporting a vulnerability
No system is perfect. If you find a vulnerability, please report it rather than exercising it, and give us a reasonable chance to fix it before disclosing. Write to legal@webzy.online.
The binding documents are the Privacy Policy and Terms of Service. Where this page and those disagree, those win.