LEGAL · PRIVACY

Privacy Policy

How ezy handles account, training, nutrition, profile and device-session data.

English version · Version 1.0 · Published 29 September 2026

ezy – Privacy Policy

Version: 1.0 Effective date: 29 September 2026 Last updated: 29 September 2026 Services covered: the ezy Android application, the ezy.hu website, and the related backend, support and administration systems.

1. Data Controller

The data controller and operator of ezy is:

  • Name: Szekeres Benjámin
  • Legal form: natural person
  • Location: Somogy County, Hungary
  • Website: ezy.hu
  • Contact and privacy e-mail: szekeresbenjamin14@gmail.com

The Data Controller determines the purposes and essential means of personal data processing carried out in connection with ezy.

2. Purpose and Scope of this Policy

This Privacy Policy explains what personal data ezy processes, for what purposes and on what legal bases, how long data is retained, who may access it, which processors and technical service providers are used, and what rights users have.

This Policy applies in particular to:

  • user accounts and authentication;
  • profile and application settings;
  • workout, body and progress data;
  • nutrition, food, meal and recipe data;
  • barcode scanning;
  • sharing of workout plans, splits, foods and meals;
  • the support ticket system;
  • device, session and version management;
  • security and technical logging;
  • the ezy.hu website and ezy backend infrastructure.

3. Data Protection Principles

ezy processes personal data in accordance with the principles of lawfulness, fairness, transparency, purpose limitation, data minimisation, accuracy, storage limitation, integrity, confidentiality and accountability.

ezy:

  • does not sell users' personal data;
  • does not provide personal data to advertising data brokers;
  • does not currently send marketing e-mail campaigns;
  • does not make marketing consent a condition of registration;
  • does not intend to process more data than is necessary for the service.

4. Data Processed by ezy

4.1. Account and Identification Data

ezy may process:

  • e-mail address;
  • internal user identifier;
  • username;
  • display name;
  • user role;
  • account creation and modification timestamps;
  • account status;
  • e-mail verification status;
  • type and version of accepted legal documents;
  • time of acceptance or acknowledgement;
  • technical evidence necessary to demonstrate the legal declaration.

4.2. Passwords, Authentication and Sessions

Passwords are not stored in readable form. ezy stores password-related information only as a modern, secure password hash.

ezy may also process:

  • e-mail verification tokens;
  • password reset tokens;
  • active sessions;
  • session identifiers;
  • access and refresh tokens or their secure representations;
  • token revocation information;
  • login and logout events;
  • device-related session data.

4.3. Profile Data

ezy may process:

  • display name;
  • username;
  • profile image;
  • biography, where the feature is available;
  • gender;
  • selected language;
  • application settings;
  • privacy and sharing settings.

Profile images are stored on the Hungarian VPS infrastructure used by ezy.

4.4. Body and Progress Data

ezy may process:

  • body weight;
  • height;
  • weight and body history;
  • changes in body data;
  • recording dates;
  • progress statistics and charts.

Individually or in combination, these data may reveal information about a user's physical condition or lifestyle.

4.5. Workout Data

ezy may process:

  • custom exercises;
  • exercise names and descriptions;
  • workout plans and splits;
  • weekly plans and rest days;
  • sets and repetitions;
  • weights used;
  • left/right side performance;
  • RIR, RPE and failure data where used;
  • rest time;
  • workout notes;
  • daily and historical workout logs;
  • personal records;
  • calculated performance metrics;
  • workout statistics.

4.6. Nutrition Data

ezy may process:

  • foods created by users;
  • food names and barcodes;
  • calories;
  • protein;
  • carbohydrates;
  • fat;
  • fibre;
  • daily food logs;
  • consumed quantities;
  • meals and recipes;
  • recipe ingredients;
  • daily calorie and macronutrient goals;
  • nutrition history and statistics;
  • public foods and meals.

4.7. Barcode Scanning and Camera

When barcode scanning is used, the application may access the device camera with the user's permission.

The purpose of camera access is to recognise product barcodes. ezy does not intend to retain the raw camera image. The recognised barcode value and the related food record may be retained.

A barcode may be used to:

  • find an existing food;
  • add a food to the daily log;
  • start creating a new food.

4.8. Shared and Public Content

ezy may allow users to:

  • share splits and workout plans;
  • share weekly plans;
  • share meals and recipes;
  • create public foods;
  • create public meals.

Content deliberately made public by a user may be viewed by other ezy users and, depending on the feature, may be imported into their own accounts.

4.9. Support Tickets

ezy may process:

  • ticket identifier;
  • subject;
  • category;
  • description;
  • user messages;
  • support replies;
  • ticket status;
  • creation, modification and closure timestamps;
  • archive and restore data;
  • identifier of the administrator handling the ticket;
  • technical troubleshooting information voluntarily provided by the user.

Archiving does not mean immediate permanent deletion.

4.10. Device, Session and Version Data

ezy may process:

  • application-level device identifiers;
  • operating system and version;
  • application version;
  • session status;
  • last activity time;
  • release/update channel;
  • user role;
  • update eligibility group;
  • technical identifiers handled by ezy's own systems for notification features, where applicable.

ezy currently does not use a separate external push notification provider.

4.11. Technical and Security Logs

To the extent necessary to protect the service, ezy may process:

  • request identifier;
  • timestamp;
  • API endpoint;
  • HTTP status code;
  • application version;
  • device-related technical information;
  • error code;
  • failed login attempts;
  • data relating to failed, expired or revoked tokens;
  • IP address or a hashed/pseudonymised representation;
  • security events;
  • rate-limit events.
PurposeData involvedMain legal basis
Account creation and managemente-mail, account ID, password hash, basic profile dataGDPR Art. 6(1)(b) – performance of a contract
Login and session managementaccount ID, tokens, session and device dataGDPR Art. 6(1)(b); security aspects may rely on Art. 6(1)(f)
E-mail verificatione-mail, token, timestampGDPR Art. 6(1)(b), and legitimate interest in security
Password resete-mail, reset token, security logsGDPR Art. 6(1)(b), and Art. 6(1)(f)
Profile featuresprofile and settings dataGDPR Art. 6(1)(b)
Workout planning and logsexercises, plans, sets, repetitions, weights, statisticsGDPR Art. 6(1)(b); where special-category data is involved, an appropriate Art. 9 condition is also required
Nutrition featuresfoods, meals, logs, macros, goalsGDPR Art. 6(1)(b); where special-category data is involved, an appropriate Art. 9 condition is also required
Body and progress trackingweight, height, body historyGDPR Art. 6(1)(b); where special-category data is involved, an appropriate Art. 9 condition is also required
Sharing featurescontent selected by the user for sharingperformance of the requested service; consent where required
Supportaccount data, tickets, messagesGDPR Art. 6(1)(b); Art. 6(1)(f) for legal claims and abuse prevention where appropriate
Security and abuse preventiontechnical logs, IP/pseudonymised IP, token and device dataGDPR Art. 6(1)(f) – legitimate interests
Debugging and system operationerrors, request IDs, technical logsGDPR Art. 6(1)(f)
Compliance with legal obligationsdata required for the relevant obligationGDPR Art. 6(1)(c)
Establishing, exercising or defending legal claimsnecessary account, log and support dataGDPR Art. 6(1)(f) and applicable law
Producing anonymous, aggregated statisticsworkout and nutrition data necessary for anonymisationan appropriate legal basis before anonymisation; where special-category data is involved, an appropriate Art. 9 condition

Body weight, body history, certain workout and nutrition data, goals, and metrics derived from them may, depending on the circumstances, reveal information about a user's physical or health status.

Where data or a combination of data qualifies as health data or another special category of personal data under the GDPR, an appropriate condition under Article 9 is required in addition to the general legal basis.

ezy does not treat general acknowledgement of this Privacy Policy as automatic explicit consent to every possible processing of special-category data. Where explicit consent is required for a specific processing activity, ezy must request it separately in a clear and withdrawable manner.

7. Anonymous and Aggregated Statistics

ezy may produce anonymous or aggregated statistics from workout and nutrition data entered by users in order to understand and improve the service and analyse general trends.

Statistical outputs must not allow a user to be reasonably re-identified.

Anonymisation measures may include removing direct identifiers, aggregation, suppressing or combining groups with very small numbers, and other technical measures intended to reduce re-identification risk.

8. Minors

Independent use of ezy is permitted from the age of 16.

A user under 16 may use ezy only with the appropriate consent and supervision of a parent or legal guardian.

If ezy becomes aware that a user under 16 is using the service without the required consent, ezy may restrict the account, request evidence of consent, or terminate the account in accordance with applicable law.

9. Retention Periods

Data categoryRetention period
Active account and core account datafor the lifetime of the account
Data marked for account deletionup to 30 days in quarantine, followed by deletion from active systems unless a legal or security reason requires retention
Backupsrotating retention of up to 90 days
Technical and security logsup to 90 days, unless required for a documented incident or legal claim
E-mail verification tokennormally 30 minutes and never more than 24 hours
Password-reset token30 minutes
Expired token recordsup to 30 days
Active support ticketfor the duration of handling the issue
Closed support ticketgenerally 24 months
Archived support ticketgenerally up to 24 months, followed by permanent deletion
Support case retained for security or legal reasonsup to 3 years where documented and justified
Profile imageuntil replacement, deletion or account termination
Workout, body and nutrition logsfor the lifetime of the account unless deleted earlier by the user
Evidence of legal-document acceptanceas long as necessary for accountability and legal claims

ezy may use automated cleanup processes. Any exception to the normal retention period must be lawful, documented, time-limited and auditable.

10. Account Deletion and 30-day Quarantine

After an account deletion request, ezy may place data designated for deletion into quarantine for up to 30 days.

After 30 days, personal data must be deleted from active systems except for the minimum data that must lawfully be retained for a legal obligation, security incident or legal claim.

Deleted data may remain in backups until the backup rotation period of up to 90 days expires.

11. Recipients, Processors and Technical Providers

11.1. VIPY

ezy uses VIPY for VPS and hosting infrastructure.

Its role may include VPS infrastructure, hosting the backend, storing the database, storing profile images and related server-side files, and providing technical infrastructure for backups where backups are maintained on the VPS.

The primary ezy server infrastructure is located in Hungary.

11.2. Cloudflare

ezy may use Cloudflare for DNS, proxy/CDN, network protection and security.

Cloudflare may process technical traffic data including IP address, network metadata, HTTP request metadata, and security or bot-protection information.

11.3. Google Play

The Android application may be distributed through Google Play. Google may process Play-account, device, installation and related data under Google's own privacy terms.

11.4. Self-hosted E-mail Infrastructure

ezy does not currently use a separate external e-mail-sending processor for service e-mails. E-mail services are operated on ezy's own VPS infrastructure.

11.5. Push Notifications

ezy currently does not use a separate external push notification provider.

11.6. Administrators and Support Personnel

ezy administrators and support personnel may access personal data only to the extent necessary for their responsibilities.

12. Transfers Outside the EU/EEA

The primary VPS and database infrastructure used by ezy is located in Hungary.

Cloudflare and Google operate global infrastructures, so some technical data may be processed outside the European Economic Area.

Any such transfers must use an appropriate transfer mechanism under applicable data-protection law.

13. Data Security

ezy may apply risk-appropriate technical and organisational safeguards, including:

  • HTTPS/TLS;
  • modern password hashing;
  • access controls;
  • separation of administrative permissions;
  • token expiry and revocation;
  • rate limiting and brute-force protection;
  • firewalls;
  • security and technical logging;
  • backups;
  • system and dependency updates;
  • incident monitoring;
  • pseudonymisation where appropriate;
  • limiting direct public access to the database.

14. Personal Data Breaches

If a personal data breach occurs, ezy will take necessary containment and recovery measures, document the event, identify affected data and users, assess the risk, and notify the competent supervisory authority and affected users where required by applicable law.

15. User Rights

Subject to applicable law, users may have the right to:

  • access their personal data;
  • rectify inaccurate data;
  • request erasure;
  • restrict processing;
  • data portability;
  • object to processing based on legitimate interests;
  • withdraw consent where processing is based on consent;
  • exercise rights related to automated decision-making where relevant.

16. Exercising Data Protection Rights

Requests may be submitted to:

szekeresbenjamin14@gmail.com

As a general rule, ezy responds within one month of receiving a request. This period may be extended where permitted by applicable law.

17. Complaints and Judicial Remedies

In Hungary, the competent data protection supervisory authority is:

Hungarian National Authority for Data Protection and Freedom of Information (NAIH) 1055 Budapest, Falk Miksa utca 9–11. Postal address: 1363 Budapest, Pf. 9. E-mail: ugyfelszolgalat@naih.hu Telephone: +36 (1) 391-1400

Users may also seek judicial remedies under applicable law.

18. Cookies and Website Technologies

ezy.hu currently does not use optional marketing, advertising or user-profiling cookies and does not operate a separate analytics-cookie system.

ezy does not request cookie consent for cookies it does not use.

Strictly necessary technical mechanisms may be used by the website or infrastructure provider for security and proper operation.

If ezy later introduces analytics, marketing or other optional third-party cookies that require consent, they will not be activated before the required consent is obtained.

19. Android Permissions

ezy may request system permissions for certain functions, including:

  • camera: barcode scanning;
  • photos/images: selecting a profile image;
  • notifications: app and support notifications where available.

20. E-mail Communications

ezy may send e-mails for e-mail verification, password reset, account security events, important service changes, material changes to legal documents and support communications.

These are service or security communications, not marketing e-mails.

ezy does not currently plan marketing e-mail communications.

ezy may record:

  • document type;
  • document version;
  • time of acceptance or acknowledgement;
  • account identifier;
  • technical evidence necessary to demonstrate the declaration.

Registration may include two separate unchecked declarations:

  • “I have read and acknowledged the Privacy Policy.”
  • “I accept the Terms of Service.”

Hungarian pages:

  • /hu/privacy
  • /hu/terms

English pages:

  • /en/privacy
  • /en/terms

22. Changes to this Policy

ezy may update this Privacy Policy where a new feature is introduced, processing activities change, a new processor is engaged, retention periods change, or legal or security developments require an update.

Users will be appropriately informed of material changes through the application, website or e-mail.

23. Version History

VersionEffective dateChange
1.029 September 2026First detailed Privacy Policy

24. Contact

Data Controller: Szekeres Benjámin Location: Somogy County, Hungary Website: ezy.hu E-mail: szekeresbenjamin14@gmail.com