Ezerly
Back

Privacy Policy

Last updated: August 16, 2026

This Privacy Policy describes how Ezerly collects, uses, and protects your personal data. We comply with the Brazilian General Data Protection Law (LGPD — Lei nº 13.709/2018) and, where applicable, the GDPR.

1. Data Controller

Ezerly acts as the data controller for the personal data you provide. For privacy requests, or to reach the person responsible for data protection, write to support@ezerly.app or use the app support channel.

2. Data We Collect

Account data: email, name, preferred language, authentication provider (Google/Apple/email).

Wellness data: profiles you create (yourself, family, pets), supplement lists, dose logs, alerts, lab records and images you upload, and notes you write.

Usage data: feature usage counters, device/session metadata, and error logs. Our website uses Cloudflare Web Analytics, which reports aggregated, privacy-preserving page statistics without cookies or cross-site tracking.

Push data: if you enable notifications we store a device push token (Apple Push Notification service on iOS, Firebase Cloud Messaging on Android, or a Web Push subscription in the browser) together with your notification preferences and timezone, so reminders can be delivered to your device.

Payment data: subscription status and Stripe customer ID. Card details are processed directly by Stripe; Ezerly does not store full card data.

3. Legal Basis (LGPD art. 7 / GDPR art. 6)

Execution of contract: to provide the Service you subscribed to.

Consent: for AI processing of your supplements/labs and for push notifications, which you can revoke at any time.

Legitimate interest: to keep the Service secure, prevent fraud, and improve quality.

Legal obligation: tax and consumer-protection recordkeeping.

4. How We Use Data

To operate the Service, generate AI wellness reviews, deliver alerts, process payments, provide support, and comply with legal obligations. We do NOT sell your personal data.

5. AI Processing

AI features are opt-in. Nothing is sent to an AI provider until you explicitly allow AI processing in the app, and you can withdraw that permission at any time in Settings; the rest of Ezerly keeps working without AI.

What is sent: profile context (profile name, age, sex, stated goal, medication notes and health conditions/notes saved on the profile), your supplements, doses, schedules and adherence history, wellbeing check-in answers, and any supplement-label or lab-result photos you choose to upload together with the text extracted from them, and the messages, free-text questions and attachments you send in the AI Chat.

Who receives it: Google AI models (Gemini family), accessed through the Lovable AI Gateway acting as our processor.

Purpose: the data is sent so the provider can generate the output you requested. Ezerly does not sell your data. Lovable and Google process it under their own terms and their applicable privacy and data-protection commitments.

Withdrawal and deletion: you can withdraw permission at any time in Settings, which stops further AI processing. Deleting your account erases the associated data as described in Data Retention.

6. Subprocessors

Supabase (hosting/database/storage), Cloudflare (edge runtime and Cloudflare Web Analytics), Stripe (payment processing), Apple (authentication and Apple Push Notification service), Google (Firebase Cloud Messaging for Android push), Google (authentication and, when you allow AI processing, the AI models accessed through the Lovable AI Gateway). Each provider processes data under its own terms and its applicable security and data-protection commitments.

7. Data Retention

We retain account and wellness data while your account is active. You can delete your account in Settings → Delete account, or read ezerly.app/delete-account to request deletion without opening the app. When you delete your account, deletion from Ezerly's own systems (database and storage) runs immediately and is completed within 30 days at the latest, except records we must retain to comply with legal obligations (e.g., tax records for 5 years). Copies held by our processors are deleted according to each provider's contracted retention and deletion terms; we do not promise a provider-side deletion deadline we cannot verify. AI processing of health, sensitive or dependent data is currently disabled in the app, so this version does not send such data to an AI provider. We can only state what we control: our own systems and what we send. We do not make claims about data an AI provider may already hold from earlier processing or about provider-side retention we cannot independently verify.

8. Security

We apply industry-standard controls: encryption in transit (TLS), Row-Level Security on all database tables, private storage buckets, and least-privilege service accounts. No system is 100% secure, but we take reasonable measures to protect your data.

9. Your Rights (LGPD art. 18)

You may request confirmation of processing, access, correction, anonymization, portability, deletion, information on data sharing, and revocation of consent. Send requests to support@ezerly.app or through the app support channel; we respond within 15 days.

10. International Transfers

Some subprocessors may process data outside Brazil. We rely on adequacy decisions or standard contractual safeguards recognized by the ANPD.

11. Dependent Profiles (Children & Other Dependents)

You must be at least 18 (or the age of majority in your jurisdiction) to create an Ezerly account. The account itself always belongs to an adult account holder.

Data about a child or other dependent (e.g., an aging parent) may only be entered by a parent, legal guardian, or other person who has the legal authority and consent required to manage that dependent's data. When you create such a profile you must tick a separate declaration and state its basis (parent/legal guardian, authorized caregiver, or — for an animal — owner). We store that declaration, its version and the moment it was made as an audit record; the profile is not created without it.

Categories of dependent data we may store: name, date of birth, sex, main wellness goal, sleep/meal/workout times, optional medication notes and health conditions/notes, supplement and routine information, dose adherence history, supplement inventory and refill data, safety and interaction alerts, optional wellbeing check-in answers, optional lab-report uploads and extracted lab markers, and the outputs of any AI reviews generated for that profile.

Purpose: this data is used only to operate the Service for that profile (organizing routines, alerts, and optional AI wellness reviews). AI processing is optional and is recorded as a single permission at the account level, given by the account holder; it applies to the AI actions the account holder starts, including those about a dependent profile. Ezerly does not run AI reviews automatically in the background — an AI request is only made when the account holder asks for one. Permission can be withdrawn at any time in Settings.

Retention and deletion: dependent-profile data is retained while the profile exists. You can delete any profile from within the app as long as it is not the only profile on the account, which removes all of the categories listed above for that profile, including uploaded lab-report and label images. The last remaining profile cannot be deleted on its own — it is removed together with the account, via Settings → Delete account or ezerly.app/delete-account, which erases all associated profiles.

12. Changes

We may update this policy. Material changes will be notified in-app or by email at least 15 days before taking effect.