Privacy & Trust Center
Privacy Policy
Transparency and user trust are core to EcomBrowser. Learn how we protect your data, secure your AI prompts, and safeguard your creative assets.
Effective Date: August 30, 2026 • GDPR & CCPA Compliant
1. Overview & Commitment
At EcomBrowser ("we", "us", "our"), protecting your personal data and creative content is our highest priority. This Privacy Policy details how we collect, use, store, and protect your information when you interact with our AI workspace platform, tools, and services.
We adhere strictly to international privacy frameworks including the General Data Protection Regulation (GDPR), California Consumer Privacy Act (CCPA), and global data protection standards.
Privacy Protections
We do not sell your personal data to third parties.
Your inputs and generated assets remain confidential under strict encryption.
2. Information We Collect
We collect information necessary to provide, optimize, and secure our services:
• Account Information: Name, email address, password hashes, and billing details when subscribing.
• Input Prompts & Content: Text, images, code snippets, and audio uploaded to run tools (including AI generations).
• Technical & Usage Data: IP address, browser type, device information, feature usage stats, and error logs.
• Communication Data: Feedback, support tickets, and correspondence with our team.
Privacy Protections
Payment card numbers are processed directly by PCI-compliant payment gateways (Stripe/PayPal) and are never stored on our servers.
3. AI Model Training & Data Isolation
A primary concern of AI users is data privacy regarding AI model training:
1. Private Prompts & Outputs: Your private prompt inputs and generated outputs on paid subscriber plans are NOT used to train or fine-tune public foundation AI models.
2. Enterprise Data Isolation: Enterprise workspace data operates in isolated cloud environments with zero data retention policies on model providers.
3. Third-Party AI API Providers: When using frontier models (OpenAI, Anthropic, Google Gemini), data sent to provider APIs is subject to strict enterprise non-training agreements.
Privacy Protections
Zero-data-retention options available for Enterprise customers.
Your proprietary code, documents, and designs remain strictly private to your team.
4. How We Use Your Information
We use collected data solely for legitimate operational and product enhancement purposes:
• To authenticate your identity and deliver personalized AI tool features.
• To calculate and deduct credit balances accurately based on model usage.
• To maintain platform security, detect fraud, and prevent malicious automated abuse.
• To send essential transaction receipts, security updates, and service announcements.
Privacy Protections
You can opt out of promotional communications at any time in your account settings.
6. Data Sharing & Third-Party Vendors
We only share your information with trusted third-party service providers necessary to operate the Platform:
• Cloud Hosting Infrastructure (AWS, Vercel, Supabase)
• AI Frontier Model Providers (OpenAI, Anthropic, Google Cloud) under enterprise privacy contracts
• Payment Processors (Stripe) for secure billing execution
All vendors are bound by Data Processing Agreements (DPAs) requiring strict confidentiality and security compliance.
Privacy Protections
We require all infrastructure vendors to maintain SOC-2 and ISO-27001 certifications.
7. Your Rights & Data Controls
Depending on your location, you possess comprehensive rights regarding your personal data:
• Right to Access: Request a copy of all personal data held by EcomBrowser.
• Right to Rectification: Correct inaccurate or outdated information.
• Right to Erasure ("Right to be Forgotten"): Request permanent deletion of your account and associated history.
• Right to Data Portability: Export your prompts, generations, and account data in JSON/CSV format.
Privacy Protections
Account data deletion requests can be initiated directly inside Account Settings -> Security.
8. Data Security & Retention
We employ end-to-end encryption in transit (TLS 1.3) and at rest (AES-256) across all database clusters. Routine vulnerability scans, automated backups, and penetration testing safeguard system integrity.
We retain personal data only for as long as your account remains active or as required by financial auditing laws. Upon account deletion, all personal data is permanently scrubbed within 30 days.
Privacy Protections
All database backups are encrypted with enterprise-grade AES-256 keys.