Google Analytics and Microsoft Clarity run automatically. Choose whether to allow optional PostHog product analytics and records of registration sources and pages that trigger purchases. Essential storage remains available.

EzImageAI image editor mark

Privacy Policy

How EzImageAI handles account data, private image-editing media, analytics consent, and retention.

Last updated: October 8, 2026

This policy explains how EzImageAI handles information when you use the public image editor, prepare a short-lived draft, use an available Nano Banana 2 Lite 1K guest trial, create an account, or use the signed-in editor. EzImageAI is an independently operated service run by an individual. Its operator is responsible for the information handled by the service and can be reached through the Contact page for privacy questions and requests.

Information EzImageAI handles

EzImageAI handles account and authentication records, subscription and credit-ledger records, product settings, and operational records needed to create and recover an edit. When you use the editor, the service also handles the source image, your edit instruction, quotes, generation status, moderation evidence, and resulting image.

If you contact support, report prohibited content, or appeal a decision, EzImageAI handles your reply address, description, references, and correspondence to investigate and respond. The operator limits access and disclosure to what is needed for that review, user protection, or applicable legal obligations. Do not include unnecessary personal data or copies of illegal content in a report.

The public homepage can prepare a short-lived draft containing the source image, selected image product and output settings, and instruction. When the Nano Banana 2 Lite 1K guest trial is enabled and you continue, EzImageAI creates a temporary anonymous user and session to authorize one private source image, one instruction, one generation job, and one watermarked preview. The trial uses sponsored credits and does not create a subscription or payment charge. Other paid image products and account features require the access shown by the product.

To enforce trial limits and protect the service, EzImageAI stores pseudonymous HMAC values derived from the temporary session, a browser device identifier, the trusted network address, and a normalized subnet. Stored values are not the raw identifiers. This evidence supports security, rate limits, replay prevention, and sponsored-risk controls; it is not used for advertising.

Private media and access

Registered source images and results are private account-scoped assets. Guest media is private and scoped to its temporary anonymous owner. EzImageAI does not publish these assets to a public gallery. The application checks ownership and uses short-lived signed URLs when a browser needs to display or download private media. Anonymous trial outputs are watermarked.

If you sign in or register from an active trial, EzImageAI can create an expiry-bounded account-link grant before revoking the anonymous session. The grant lets the registered account view and download the same watermarked result until its original expiry. It does not transfer sponsored credits, extend retention, add the result to History, or enable Edit Again.

EzImageAI may send the minimum necessary edit input to configured hosting, storage, moderation, payment, and image-processing services so they can perform the requested function. Those services do not own EzImageAI job, credit, or subscription state.

Before generation, EzImageAI screens text instructions using Waffo. A prompt scan receives the text instruction and scan settings, without your source image, account email, or payment details. SeeAPI receives a short-lived access URL to check private source and generated images. New temporary editor references are checked when you click Generate and must receive positive approval before the image model runs; a failed check stops generation and releases its credit hold. Temporary detector failures may receive bounded retries; exhausted or incomplete checks do not authorize generation or result access. Credit handling follows the persisted job and ledger state. Confirmed content blocks and content-review decisions remain blocked. Authorized administrators may inspect the original instruction or image to recheck, approve, or restrict it. Access and decisions are audited. EzImageAI retains limited safety decisions and request references without copying raw instructions or private image URLs into these moderation audit records. A billing-account record retains whether the one-time output-block credit waiver has been used, even after related media or job history is removed.

Optional PostHog product analytics runs only after analytics consent. These funnel events use controlled values such as plan, public product key, status, credit bucket, and latency bucket. Their payloads reject prompts, file names, email addresses, raw job IDs, cookies, tokens, private asset or signed URLs, Provider or model details, cost details, and raw Provider responses.

With the same optional consent, a first-party cookie retains your first landing page, external referring origin and limited source, medium and campaign tags for up to 30 days. When you register, the service saves that source once on your account. When you start a subscription or credit-pack checkout, it records the page that prompted the purchase and copies both source snapshots to the confirmed purchase for administrator review. It excludes URL query strings and fragments, private resource identifiers, email addresses and authentication tokens. Declining consent clears this optional browser storage and prevents new source collection; unavailable and historical sources remain unknown. Existing account and purchase snapshots follow account and billing-record retention, and subscription renewals keep the original purchase source.

When configured, Google Analytics and Microsoft Clarity load automatically without waiting for the cookie banner choice. Google Analytics measures visits to public pages using page addresses without query parameters or fragments and an origin-only referrer; its advertising signals are disabled. Microsoft Clarity uses its standard website integration across public and signed-in pages, including the editing workspace. EzImageAI does not add page exclusions, full-page masking, or navigation-based recording stops. Clarity's own project settings and built-in protections govern what it records; visible page content and media previews may be included. These services may process page addresses, interactions, browser, device, and network information for their analytics features.

The cookie banner choice controls optional PostHog product analytics and registration and purchase source analytics. Declining it does not disable Google Analytics or Microsoft Clarity and does not prevent essential authentication, security, billing, draft, or editing storage from working.

Why information is used

Information is used to provide and secure the service; verify ownership; moderate inputs and outputs; quote, reserve, charge, or release credits; process subscriptions; recover asynchronous work; prevent abuse; answer support requests; and understand low-sensitivity product funnel performance when consent has been granted.

Retention and deletion

Public-page drafts expire after no more than one hour. Media used by the Nano Banana 2 Lite 1K guest trial is access-bounded and scheduled for deletion no later than 24 hours after the trial job is created. Clean, unwatermarked staging bytes are deleted before the result becomes available. New references uploaded in the signed-in editor expire after 24 hours and are removed through the storage lifecycle policy. Physical deletion can occur after that access deadline. Generated results remain independent of reference expiry. Registered library media and generated outputs retain the existing target of 30 days, with 7 days for failed-job cleanup.

Billing, credit-ledger, security, audit, and legal records may require different retention because they support financial integrity, dispute handling, fraud prevention, or legal obligations. Deleting or expiring a private asset prevents new access links and schedules the underlying object for deletion through the asynchronous cleanup path. Backup and infrastructure copies may take additional time to age out.

Your choices

You may accept or decline optional PostHog product analytics and source analytics. Available account, subscription, and media controls can be used to review or delete eligible data. For an access, correction, deletion, portability, restriction, or privacy question, contact the operator. The response depends on applicable law and on records EzImageAI must retain for security, billing, or legal reasons.

Security and changes

EzImageAI uses owner checks, private storage, short-lived access, moderation, idempotent jobs, and restricted administrative diagnostics to reduce risk. No online service can promise absolute security. Material changes to this policy will be dated on this page.