EZ File Manager
Back to site

Legal

Privacy Policy

This Privacy Policy explains what personal information EZ File Manager collects, why, what stays on your own devices, who we share it with, how long we keep it, and the rights you can exercise against us. It applies to the EZ File Manager Android app, the desktop/native agent, and the web app at ezfilemanager.aicanadiansolutions.ca — they all share one account and one policy.

Effective date: July 16, 2026 · Developer: AI Canadian Solutions ("we", "us", "our")

1. Who we are and what this covers

EZ File Manager is a file-deduplication and file-management service operated by AI Canadian Solutions, a Canadian developer. The Service consists of the Android app, a native desktop agent you install on your computers, the web app, and the server-side account that ties them together. This policy is written to satisfy our obligations under the federal Personal Information Protection and Electronic Documents Act ("PIPEDA") and, for residents of Quebec, the Act respecting the protection of personal information in the private sector as amended by Law 25 ("Quebec Law 25").

The short version: your file contents stay on your devices

Scanning and duplicate detection run on your own machine or phone, inside the app and the native agent. What is sent to our servers is metadata only — file path, name, size, timestamps, media dimensions and a content fingerprint (a BLAKE3 / xxh3 hash). The bytes of your photos, videos, documents and project files are never uploaded to us as part of indexing or duplicate detection, and a hash cannot be reversed back into the file it came from. The only file contents we ever hold are the ones you deliberately place with us yourself (Secure Vault uploads, Vault imports from a connected cloud account, and files you push from a phone into your device inbox).

2. Information we collect

Account information

  • Account data — your name, email address, a hash of your password (never the password itself), email verification state, plan/subscription status and preferences.
  • Payment data — handled entirely by Stripe, our payment processor. We never see or store your card number; we hold only subscription status and Stripe references.

File index (metadata only)

  • File metadata — for each file you scan: file path, file name, size, created/modified timestamps, media type, image/video dimensions and duration, EXIF timestamps, and content hashes (BLAKE3 / xxh3) used for duplicate detection.
  • Duplicate results — duplicate sets, matches and cleanup recommendations derived from that index.
  • Tags, notes and audit ledger — tags and notes you attach to files, and an append-only activity log of actions taken in your account.

Connections, devices and the agent

  • Storage sources — the drives, folders, phones and cloud accounts you register, with their labels, root paths and capacity statistics.
  • Cloud OAuth tokens — if you connect a cloud provider (e.g. Dropbox, OneDrive), we store encrypted access and refresh tokens plus the linked account name/email/ID, so we can list your cloud files for deduplication.
  • Device and agent registrations — each paired device or desktop agent: its name, platform, agent version, last-seen timestamp and pairing codes.

Content you deliberately store with us

  • Secure Vault — files you upload or import into the Vault are stored encrypted in our object storage, together with your vault password hash and salts.
  • Device inbox — files you send from a phone to your account ("send to vault") via the cloud path are stored until you move or delete them.

Technical data

  • Server and security logs — standard web-server logs (IP address, user agent, request path) kept for abuse prevention, security and debugging, rotated within 90 days.
  • Sessions and API tokens — browser sessions, "remember me" tokens, and the API/agent access tokens that let your devices talk to your account.

3. What stays local and is never collected

  • The contents of the files on your drives, phones and cloud accounts (except Vault/device-inbox content you place with us yourself, as above).
  • Peer-to-peer transfers — when you send files between your own devices over LAN P2P, the file bytes travel directly device-to-device (WebRTC). Our server only brokers the connection handshake (session codes, connection offers/answers and network candidates) and never receives the transferred files.
  • We do not collect your contacts, location, browsing history, or advertising identifiers. The Service contains no advertising and no third-party analytics or tracking SDKs.

4. How we use your information

  • To operate the Service: index your files, detect duplicates across your sources, sync your devices, and store what you put in your Vault.
  • To manage your account, subscription and billing.
  • To secure the Service, prevent abuse and debug problems.
  • To respond when you contact us for support.

We do not sell or rent personal information, we do not use your data for advertising, and we do not use your files or file metadata to train AI models.

5. The AI advisor (OpenAI as a sub-processor)

What the AI feature actually sends

The "recommended cleanup plan" narration is generated with the help of OpenAI (model: gpt-4o-mini), acting as our sub-processor. Every actual decision — which copy of a duplicate to keep, how much space is reclaimable — is made by our own deterministic rules engine, not the AI. The AI only turns the result into readable text.

What is sent to OpenAI is a compact statistical summary: duplicate-group counts, file sizes, reclaimable bytes, and the labels of your storage sources (e.g. "Laptop SSD", "Dropbox"). No file contents, no file names and no file paths are sent. OpenAI's API terms prohibit it from using API data to train its models. If the AI call fails or is unavailable, the Service falls back to a plain rules-generated summary.

6. Who we share information with

We share personal information only with the service providers below, only as needed to run the Service:

ProviderRoleWhat they receive
DigitalOcean (Toronto, Canada)Hosting of our servers and databaseAll server-side data described above, stored in Canada.
StripePayment processingYour payment card details (entered directly with Stripe) and billing identity. We never hold card numbers.
OpenAI (United States)AI narration of cleanup plansAggregate duplicate statistics and source labels only — see Section 5.
S3-compatible object storageEncrypted storage of Vault and device-inbox file blobsThe encrypted content you deliberately store with us.
Cloud providers you connect (e.g. Dropbox, Microsoft OneDrive)Sources you linkThey receive API requests made on your behalf under the OAuth consent you granted; you can revoke this at any time in the provider's settings.

We may also disclose information if required by law, court order, or to protect the rights, safety and property of users or the public. Under PIPEDA Principle 1 (Accountability) we remain responsible for personal information we transfer to a service provider for processing, including across borders; where data leaves Canada (e.g. the statistical summaries sent to OpenAI in the United States) it is subject to the laws of that jurisdiction.

7. Retention

DataRetention
Account, file index, connections, Vault, devicesKept while your account is active; deleted within 30 days of a verified deletion request (see Section 8).
Payment and invoice recordsHeld by Stripe as long as tax and accounting law requires (typically 7 years).
Encrypted database backupsRolling backups age out within 30 days of a deletion.
Server / security logsUp to 90 days, then rotated away.
Anonymous, aggregated statistics (e.g. total bytes reclaimed)Indefinitely — cannot be linked back to any person.

8. Deletion

You can request deletion of your whole account, or of specific data, at any time. The full process, exactly what is erased, and the timeline are documented on our account & data deletion page. In short: email ezfilemanager@aicanadiansolutions.ca from the address on your account, and deletion is completed within 30 days. You can also remove individual cloud connections, devices, Vault items and index entries yourself inside the app at any time.

9. Your rights under PIPEDA and Quebec Law 25

We honour the following rights for all users, at no charge:

  • Access — ask what personal information we hold about you and receive a copy.
  • Correction — have inaccurate or incomplete information corrected.
  • Withdrawal of consent — disconnect cloud accounts and devices at any time, or withdraw consent entirely by deleting your account.
  • Deletion / de-indexing — have your personal information deleted (Section 8).
  • Portability — receive the data we hold about you in a machine-readable format (a formal right under Quebec Law 25; we extend it to all users).
  • Complaint — complain to us first (contact below); you may also complain to the Office of the Privacy Commissioner of Canada, or, in Quebec, the Commission d'accès à l'information.

Automated decision-making (Quebec Law 25)

No decision with legal or significant effect on you is made exclusively by automated processing. The AI advisor (Section 5) only narrates recommendations; which duplicate to keep is decided by a transparent, deterministic rules engine, and nothing is ever deleted from your devices without your explicit action. You always review and confirm any cleanup yourself.

Breach notification

If a breach of security safeguards creates a real risk of significant harm to you, we will notify you and the Office of the Privacy Commissioner of Canada as soon as feasible, in accordance with PIPEDA's Breach of Security Safeguards Regulations, and keep records of every breach for at least 24 months. For Quebec residents we will also notify the Commission d'accès à l'information promptly, as Law 25 requires.

10. Security

  • All traffic between your devices, the agent, and our servers is encrypted in transit (TLS/HTTPS).
  • Passwords are stored only as strong one-way hashes; cloud OAuth tokens are stored encrypted.
  • Vault content is stored encrypted in object storage, protected by a separate vault password.
  • Access to production systems is restricted, and account activity is recorded in an append-only audit ledger.

11. Children

The Service is not directed at children. You must be at least 13 years old to create an account (and, if you reside in Quebec, at least 14 years old, with parental consent required under age 14 per Law 25). If we learn we have collected personal information from a child below the applicable age without verified parental consent, we will delete it.

12. Google Play data-safety summary

For users of the Android app, this policy aligns with our Google Play Data Safety declaration:

  • Data collected — account identifiers (name, email), app activity in the form of file metadata (names, paths, sizes, timestamps, content hashes) and duplicate results, device/agent identifiers, and any files you deliberately store in the Vault or device inbox.
  • Data shared — only with the processors in Section 6; never sold, never shared for advertising.
  • Encryption — all data is encrypted in transit; Vault content and cloud tokens are encrypted at rest.
  • Deletion — a public, no-login deletion path exists at /account-deletion.

13. Changes to this policy

If we make material changes we will update this page, change the effective date above, and — for significant changes — notify you by email or an in-app notice before the change takes effect.

14. Contact

Privacy questions, access requests and complaints: aicanadiansolutions@gmail.com. Deletion requests: ezfilemanager@aicanadiansolutions.ca. This page is reachable at /privacy with no sign-in required. See also our Terms of Use and account & data deletion page.

EZ File Manager
Home Privacy Terms Delete account & data Sign in
© 2026 EZ File Manager · AI Canadian Solutions