Last updated: September 23, 2026
Legal

Privacy Policy

Ezkey mobile app, ezkey.org, and the alpha community instance

Short version Ezkey is primarily self-hosted software: when you enroll with an organization that runs its own backend, that organization is the controller of data on that backend. The Ezkey project also operates a separate alpha community instance on ezkey.online for evaluation; for that instance the project is the operator. The mobile app does not send analytics to the project. The static ezkey.org site remains cookie-light as described below.

1. Who we are

Ezkey is an independent software project led by Marc Gagnon (Pincourt, Québec, Canada). It produces the Ezkey Android mobile app (currently in internal testing — not listed on Google Play or other app stores), the ezkey.org website, and an optional alpha community instance at ezkey.online. The project is in active development and remains alpha.

Privacy inquiries: privacy@ezkey.org — General: support@ezkey.org

2. The two-layer model — self-hosted software

Important distinction. Ezkey is a software platform that organizations can self-host. Publishing MIT-licensed source code is not the same as selling a SaaS product. Understanding that distinction matters for this policy.

Layer 1 — Ezkey the project (software publisher). The Ezkey project publishes software (mobile app, backends, Admin UI, documentation) under MIT. For ordinary self-hosted deployments, the project does not operate your organization’s authentication servers or databases and has no visibility into how you use a backend that you (or a third party) host. The mobile app does not integrate project-operated analytics, crash reporting, or advertising SDKs.

Layer 2 — Your organization’s self-hosted backend. To use Ezkey with your own stack, you enroll with an organization that runs its own Ezkey backend on its own infrastructure. That organization is the data controller for any personal data processed on their server. You should consult their privacy policy for information about how they handle your data.

This section does not cover the community instance on ezkey.online — see the next section.

3. Community instance (ezkey.online)

Alpha evaluation only. The community instance is operated by the Ezkey project / Marc Gagnon so evaluators can try a live stack without self-hosting. It is not a sold SaaS product, has no SLA, and is not a production service.

For the community instance hosted at ezkey.online (including related hosts such as admin-ui.ezkey.online, admin-api.ezkey.online, and demo-acme.ezkey.online), the Ezkey project is the operator of that backend and is the controller for personal data processed there in the course of evaluation (for example account or enrollment data you create while using the instance).

Further honesty bounds for evaluators are described on Community instance — alpha on ezkey.online.

4. Data stored on your device

The Ezkey app stores the following data locally on your device only:

Uninstalling the app removes all of the above data from your device. Any record of your enrollment on your organization’s backend remains subject to their own data retention policy.

5. Data sent over the network

The app communicates exclusively with the backend URL obtained from the QR code you scan during enrollment. That URL is the endpoint of an Ezkey server — typically your organization’s self-hosted deployment, or, for community evaluation, the project’s ezkey.online instance. The app sends:

The app also receives data from that backend. When a contextual approval request is initiated, the pending response may include a title and message describing the action to approve (for example: “Document Signature Request — Please approve the signing of the NDA with partner Acme Corp.”). This data originates from the backend operator, is displayed to you after the app verifies its cryptographic signature, and is not stored beyond the authentication session.

For a third-party self-hosted backend, the Ezkey project does not receive that traffic. For the community instance, protocol traffic is processed by the project-operated backend (see section 3).

No analytics, crash reports, telemetry, or advertising data is transmitted by the app to the Ezkey project.

6. Android permissions

Permission Why it is requested Data retained?
Camera To scan the QR code displayed during enrollment. Frames are processed on-device and immediately discarded; no image is stored or transmitted. No
Internet To communicate with your organization’s self-hosted backend. No (see section 5)
Biometric / device credential
(optional local confirmation)
The app may ask for a strong biometric or the device PIN, pattern, or password before approving or denying a request, and before lowering the local confirmation setting. Biometric templates and device credentials remain managed by Android and are not sent to Ezkey. This confirmation is enforced by the app flow; the backend receives no cryptographic proof that it occurred or was bound to the response signature. No

7. Third-party SDKs and services

The Ezkey app does not integrate any SDK that collects user data, including but not limited to advertising SDKs, analytics SDKs (Firebase Analytics, Mixpanel, etc.), or crash-reporting SDKs (Crashlytics, Sentry, etc.).

The app uses the following open-source libraries for their stated technical purpose:

None of these libraries transmit data to their authors or any third party.

8. The ezkey.org website

The ezkey.org website is a static site hosted on Cloudflare Pages. It does not use cookies, does not set tracking pixels, and does not load third-party analytics scripts.

Cloudflare may collect standard web server logs (IP address, user agent, timestamp) for security and infrastructure purposes, subject to Cloudflare’s privacy policy. The Ezkey project does not receive or process those logs.

9. Children

The Ezkey app is not directed at children under 13 years of age. We do not knowingly collect personal information from children under 13. If you are under 13, please do not use the app.

10. Your rights

Data on your device

You can delete all data stored by the app at any time by uninstalling it from your device. Android’s “Clear data” function in App Settings achieves the same result without uninstalling.

Data on a self-hosted organization backend

Any enrollment record or authentication history held by an organization’s self-hosted Ezkey backend is subject to that organization’s own data retention and deletion policies. Please contact that organization’s administrator to exercise your rights (access, rectification, erasure, portability) regarding that data.

Data on the community instance

For data processed on ezkey.online, contact privacy@ezkey.org. Remember that the instance is alpha evaluation infrastructure: data may already have been wiped by reseed or maintenance, and there is no backup guarantee.

Quebec residents (Act respecting the protection of personal information — Law 25)

For the mobile app and self-hosted third-party backends, the project does not collect personal information beyond what is described above. For the community instance, the project may process evaluation-related personal data as operator. Questions or requests: privacy@ezkey.org.

EU residents (GDPR)

For ordinary self-hosted deployments, your organization’s backend is the relevant controller; the Ezkey project is not the controller of that traffic. For the community instance, the project acts as controller for data processed on that evaluation backend. For personal data held by Cloudflare (web server logs for ezkey.org), refer to Cloudflare’s GDPR documentation. Contact privacy@ezkey.org for community-instance requests.

11. Data security

Cryptographic keys generated by the app are stored in the Android Keystore, which provides hardware-backed protection on supported devices. Network communication with your organization’s backend uses HTTPS. The Ezkey project recommends that organizations configure their backend with a valid TLS certificate.

Long-lived persisted application secrets, such as the enrollment proof token and the stored integration verification key, are protected separately at rest. On Android, the current reference app uses a dedicated app-level AES key in the Android Keystore to seal those values before they are written to app storage. This is distinct from the Android Keystore path used for the device’s private signing key; the app does not currently rely on one StrongBox-backed private key to decrypt every other local secret.

12. Changes to this policy

We may update this policy as the project evolves. Significant changes will be noted in the table below. The current version is always available at https://ezkey.org/privacy.html.

Date Change
September 23, 2026 Community instance (ezkey.online) disclosure; public MIT repository; corrected Google Play / “no servers” claims for alpha posture.
April 24, 2026 Initial publication.

13. Contact

For questions about this privacy policy:

Ezkey Project — Marc Gagnon
privacy@ezkey.org — privacy inquiries
support@ezkey.org — general support
Pincourt, Québec, Canada

We aim to respond to privacy inquiries within 30 days.