Data Handling

Last updated: July 14, 2026

This page explains what EZAgent Tools stores, why it is needed, and how long it is kept.

What Is Collected

DataPurposeStorage and Retention
Name and emailAccount identity, login, and connecting known activity to the correct user.Cloudflare KV while active and up to 90 days afterward.
Subscription and access statusAccess control.Cloudflare KV and Stripe.
Secure session tokenKeep the user signed in.Secure httpOnly cookie and Cloudflare KV until expiration.
IP address and approximate locationSecurity, repeat visit reporting, troubleshooting, and product analytics.Detailed first party analytics records for up to 90 days. Cloudflare may retain separate edge logs under its policies.
Visitor ID and session IDDistinguish browsers and visits without requiring a login.First party browser storage and Cloudflare KV. Detailed records are retained for up to 90 days.
Pages, clicks, timing, and referring pathMeasure feature use, daily activity, returning visitors, and likely bounce behavior.Cloudflare KV for up to 90 days. Aggregate account totals may remain with the account.
Tool page views and tool runsUnderstand which tools are opened and used.Cloudflare KV account counters and detailed analytics events.
Browser, request, and tool errorsFind bugs and failed workflows.Cloudflare KV for up to 90 days.
Deal inputsGenerate the requested output.Sent to the OpenAI API for processing and not stored afterward unless the user explicitly saves an output or workspace record.
Payment dataBilling.Stripe. EZAgent Tools does not store card numbers.

Known and Anonymous Activity

After login, activity can be associated with the account name and email. Before login, EZAgent Tools only has a browser visitor ID, session ID, IP address, and technical activity. A visitor's real name cannot be known unless the person identifies through an account or another authorized form.

What Is Not Collected by the Analytics Layer

Security and Access

The detailed EZAgent analytics report is restricted to Brian's authenticated owner account. Traffic is served over HTTPS. Authentication uses secure login links or Google login rather than stored passwords.

Deletion

Email Brian@BrianHymas.com to request deletion of account and associated usage records.