Privacy
Short version: we store what running an account requires and nothing we cannot justify. No advertising trackers, no data sold to anyone, ever.
What we store
Your email, your name, and a hashed password — never the password itself. Your workspace, your subscription state, and the record of which prompts you have unlocked.
For each session: the device label and browser string, the time it was issued, and a hashed form of the IP it came from. The hash is what lets us rate-limit abuse without keeping a log of where you have been.
Search queries
Searches are logged with their result count. Queries that return nothing drive what gets written next — that log is the single most useful thing we have for deciding which prompts to commission. Logged-in searches are associated with your account; logged-out ones are not.
Payments
Stripe processes every payment and holds the card details. We store the Stripe customer and subscription identifiers and the plan state they report back. We never see a card number.
Transactional email only by default — verification codes, password resets, billing notices. Marketing email is opt-in and the preference is on your profile page, changeable at any time.
Cookies and storage
A refresh-token cookie scoped to the auth endpoints, and the access token in your browser's local storage. Nothing else. There is no analytics or advertising cookie on this site.
Your rights
Ask for a copy of your data, or ask for it deleted, by writing to hello@webbzer.ai. Deletion removes the account, its sessions and its unlock history; billing records are retained only where tax law requires it.
Questions about any of this? Ask before you buy, not after — write to hello@webbzer.ai.