Legal
This Privacy Policy explains what personal information EZ File Manager collects, why, what stays on your own devices, who we share it with, how long we keep it, and the rights you can exercise against us. It applies to the EZ File Manager Android app, the desktop/native agent, and the web app at ezfilemanager.aicanadiansolutions.ca — they all share one account and one policy.
Effective date: July 16, 2026 · Developer: AI Canadian Solutions ("we", "us", "our")
EZ File Manager is a file-deduplication and file-management service operated by AI Canadian Solutions, a Canadian developer. The Service consists of the Android app, a native desktop agent you install on your computers, the web app, and the server-side account that ties them together. This policy is written to satisfy our obligations under the federal Personal Information Protection and Electronic Documents Act ("PIPEDA") and, for residents of Quebec, the Act respecting the protection of personal information in the private sector as amended by Law 25 ("Quebec Law 25").
Scanning and duplicate detection run on your own machine or phone, inside the app and the native agent. What is sent to our servers is metadata only — file path, name, size, timestamps, media dimensions and a content fingerprint (a BLAKE3 / xxh3 hash). The bytes of your photos, videos, documents and project files are never uploaded to us as part of indexing or duplicate detection, and a hash cannot be reversed back into the file it came from. The only file contents we ever hold are the ones you deliberately place with us yourself (Secure Vault uploads, Vault imports from a connected cloud account, and files you push from a phone into your device inbox).
We do not sell or rent personal information, we do not use your data for advertising, and we do not use your files or file metadata to train AI models.
The "recommended cleanup plan" narration is generated with the help of OpenAI (model: gpt-4o-mini), acting as our sub-processor. Every actual decision — which copy of a duplicate to keep, how much space is reclaimable — is made by our own deterministic rules engine, not the AI. The AI only turns the result into readable text.
What is sent to OpenAI is a compact statistical summary: duplicate-group counts, file sizes, reclaimable bytes, and the labels of your storage sources (e.g. "Laptop SSD", "Dropbox"). No file contents, no file names and no file paths are sent. OpenAI's API terms prohibit it from using API data to train its models. If the AI call fails or is unavailable, the Service falls back to a plain rules-generated summary.
We share personal information only with the service providers below, only as needed to run the Service:
| Provider | Role | What they receive |
|---|---|---|
| DigitalOcean (Toronto, Canada) | Hosting of our servers and database | All server-side data described above, stored in Canada. |
| Stripe | Payment processing | Your payment card details (entered directly with Stripe) and billing identity. We never hold card numbers. |
| OpenAI (United States) | AI narration of cleanup plans | Aggregate duplicate statistics and source labels only — see Section 5. |
| S3-compatible object storage | Encrypted storage of Vault and device-inbox file blobs | The encrypted content you deliberately store with us. |
| Cloud providers you connect (e.g. Dropbox, Microsoft OneDrive) | Sources you link | They receive API requests made on your behalf under the OAuth consent you granted; you can revoke this at any time in the provider's settings. |
We may also disclose information if required by law, court order, or to protect the rights, safety and property of users or the public. Under PIPEDA Principle 1 (Accountability) we remain responsible for personal information we transfer to a service provider for processing, including across borders; where data leaves Canada (e.g. the statistical summaries sent to OpenAI in the United States) it is subject to the laws of that jurisdiction.
| Data | Retention |
|---|---|
| Account, file index, connections, Vault, devices | Kept while your account is active; deleted within 30 days of a verified deletion request (see Section 8). |
| Payment and invoice records | Held by Stripe as long as tax and accounting law requires (typically 7 years). |
| Encrypted database backups | Rolling backups age out within 30 days of a deletion. |
| Server / security logs | Up to 90 days, then rotated away. |
| Anonymous, aggregated statistics (e.g. total bytes reclaimed) | Indefinitely — cannot be linked back to any person. |
You can request deletion of your whole account, or of specific data, at any time. The full process, exactly what is erased, and the timeline are documented on our account & data deletion page. In short: email ezfilemanager@aicanadiansolutions.ca from the address on your account, and deletion is completed within 30 days. You can also remove individual cloud connections, devices, Vault items and index entries yourself inside the app at any time.
We honour the following rights for all users, at no charge:
No decision with legal or significant effect on you is made exclusively by automated processing. The AI advisor (Section 5) only narrates recommendations; which duplicate to keep is decided by a transparent, deterministic rules engine, and nothing is ever deleted from your devices without your explicit action. You always review and confirm any cleanup yourself.
If a breach of security safeguards creates a real risk of significant harm to you, we will notify you and the Office of the Privacy Commissioner of Canada as soon as feasible, in accordance with PIPEDA's Breach of Security Safeguards Regulations, and keep records of every breach for at least 24 months. For Quebec residents we will also notify the Commission d'accès à l'information promptly, as Law 25 requires.
The Service is not directed at children. You must be at least 13 years old to create an account (and, if you reside in Quebec, at least 14 years old, with parental consent required under age 14 per Law 25). If we learn we have collected personal information from a child below the applicable age without verified parental consent, we will delete it.
For users of the Android app, this policy aligns with our Google Play Data Safety declaration:
If we make material changes we will update this page, change the effective date above, and — for significant changes — notify you by email or an in-app notice before the change takes effect.
Privacy questions, access requests and complaints:
aicanadiansolutions@gmail.com.
Deletion requests: ezfilemanager@aicanadiansolutions.ca.
This page is reachable at /privacy with no sign-in required. See also our
Terms of Use and
account & data deletion page.