Privacy Policy
what we store, and for how long
This policy covers EZ Website Backup at ezwebsitebackup.aicanadiansolutions.ca. It is written to be read, not to be survived. If anything here is unclear, email us and we will fix the wording.
Last updated July 24, 2026 · Data controller: AI Canadian Solutions, Ontario, Canada · Contact ezwebsitebackup@aicanadiansolutions.ca
- We store your name, email and a hashed password so you can have an account.
- For every backup we log the target URL, your crawl settings, your IP address, byte and page counts, and timestamps — for abuse prevention and rate limiting.
- Crawl archives are stored strictly to compile your file tree and ZIP, and are automatically purged from our servers within 72 hours of the backup starting.
- ZIP files are built on demand into a temporary file and deleted the instant the download completes.
- No advertising, no third-party analytics, no trackers, no sale of data. Ever.
- You can have everything deleted on request, and individual backups deleted instantly from the app.
What we collect
Your name, email address, a password stored only as a bcrypt hash (we never see the password itself), the date you verified your email, and whether the account is suspended.
Why — To create and secure your account, verify you are reachable, and let you reset a password.
For each backup: the target URL and host, your crawl settings (depth, page and size caps, scope, delay, whether JavaScript rendering or robots.txt honouring was on, any custom user-agent, any cookie string you supplied), the status, pages crawled, files found and downloaded, bytes transferred, error messages, the ownership attestation timestamp, and the IP address the request came from.
Why — To run the crawl, show you progress, enforce per-account and per-network limits, and investigate abuse complaints from site owners.
The pages, images, stylesheets, scripts and documents our crawler retrieved from the URL you gave it, stored as files on our server, plus a database index of their paths, sizes and content types.
Why — So you can browse the file tree and download the archive. This is the only reason it exists on our disk.
A session cookie, the session record in our database, CSRF tokens, and password-reset tokens. Your browser also stores a local flag remembering that you attested ownership of a given host.
Why — To keep you signed in and to block cross-site request forgery and abuse.
Standard web-server and application logs: request paths, timestamps, response codes, user agent, IP address, and error traces.
Why — To keep the service running, diagnose faults, and detect attacks.
What we never do
- We do not sell, rent, or trade personal information — there is no circumstance in which we would.
- We run no advertising network, no third-party analytics, no tag manager, no social pixels, and no cross-site trackers. The site loads no tracking scripts.
- We do not read, index, mine, republish, or train anything on the content your crawls retrieve. We do not open your archives unless you ask us to help with a specific problem, or we are compelled by law.
- We do not build advertising or behavioural profiles, and we do not make automated decisions with legal effects about you.
- We do not send marketing email. The only messages we send are email verification, password resets, and occasional service notices.
How long we keep it
A scheduled job runs every hour and deletes crawls older than 72 hours along with every file on disk belonging to them. This is not a policy we perform by hand — it is a cron-driven purge, and it runs whether or not anyone asks.
| Mirrored site files on disk | 72 hours from the start of the backup, then auto-purged |
| File index and crawl record | deleted with the mirror at 72 hours |
| ZIP archive you download | built in a temp file, deleted the moment the download finishes |
| Backup you delete yourself | files and index removed immediately |
| Account (name, email, hash) | until you ask us to delete it |
| Session records | expire and are cleared automatically |
| Password-reset tokens | expire within 60 minutes |
| Server and application logs | rotated on the server; kept short-term for diagnostics and abuse investigation |
Because of the 72-hour purge, EZ Website Backup is not long-term storage. Download what you need. Full account erasure is described on the account and data deletion page.
Legal basis for processing
For users in the UK, EEA and other places with equivalent rules, we rely on: performance of a contract (running the account and the backups you ask for); legitimate interests (keeping the service secure, enforcing rate limits, investigating abuse, preventing fraud — balanced against your rights); and legal obligation where we must retain or disclose something. We do not rely on consent for anything except optional communications, which you can withdraw at any time.
Who else touches the data
A short list of service providers, each acting on our instructions:
Hosts the server that runs the app, the database and the temporary mirrors.
Sends transactional email only — verification links, password resets, service notices. Receives your email address and the message.
When you start a backup, our server contacts the host you named. That host sees our server IP address and any user-agent or cookie you configured — not your home IP address.
We may also disclose information where we are legally required to, or where it is necessary to establish, exercise or defend a legal claim — including responding to a substantiated abuse or infringement complaint about a crawl. If a business transfer ever happened, data would move with it under this same policy.
Our infrastructure and providers may process data in Canada, the United States, and other countries. Where data leaves your region, we rely on our providers' standard contractual clauses and equivalent safeguards.
Security
- All traffic is served over HTTPS.
- Passwords are stored as bcrypt hashes, never in readable form.
- Every backup is bound to the account that created it; requests for another account's job or files are refused.
- The crawler refuses internal, private and loopback addresses to prevent it being turned against internal infrastructure.
- Per-account and per-network rate limits, signup and login throttling, and email verification are all in force.
- The shortest retention we can get away with is itself a security control: data we already deleted cannot leak.
No system is perfectly secure. If you find a vulnerability, email us — we would rather hear it from you.
Your rights
Depending on where you live (PIPEDA in Canada, GDPR in the UK and EEA, CCPA/CPRA in California, and comparable laws elsewhere) you can ask us to:
- tell you what we hold about you, and give you a copy;
- correct anything inaccurate;
- delete your account and data;
- export your data in a portable form;
- restrict or object to a particular processing activity;
- complain to your data protection authority (in Canada, the Office of the Privacy Commissioner).
Email ezwebsitebackup@aicanadiansolutions.ca from your account address. We respond within 30 days, usually in a few business days, and we never charge for it or penalise you for asking.
Children
The Service is not directed at children and is not for anyone under 16. We do not knowingly collect information from children. If you believe a child has created an account, tell us and we will delete it.
Changes to this policy
If we change what we collect or how long we keep it, we update this page and the date at the top. Material changes will be called out here. Using the Service after a change means you accept it.
Privacy questions or requests
Access, correction, export, deletion, or just a question about a line on this page — same address, real replies.
ezwebsitebackup@aicanadiansolutions.ca