Privacy Policy
This Privacy Policy explains how Ezysphere Limited ("Ezysphere", "we", "us", "our") handles personal information when you visit our website, download or use one of our applications, or contact us. It is written to be read in plain English, and it is the policy we hold ourselves to.
We collect as little as we can get away with. Most of our apps work without an account, and several work entirely offline. We do not sell your personal information, and we never have. Where an app needs something sensitive to do its job - a floor-plan photo, a body photograph, an application document - we say so explicitly in that app's privacy supplement, we process it for that purpose only, and we tell you exactly how long we keep it. You can ask us to delete everything at any time.
Contents
- Who we are
- Scope of this Policy
- Information we collect
- Sensitive information
- How and why we use it
- Legal bases
- Advertising and analytics
- Cookies and similar technologies
- Who we share it with
- International transfers
- How long we keep it
- How we protect it
- Your rights
- Region-specific rights
- Children and young people
- Automated decisions and profiling
- Security incidents
- Third-party sites and services
- Store privacy disclosures
- Changes to this Policy
- Complaints
- How to contact us
1. Who we are
Ezysphere Limited is a software studio incorporated in the Federal Republic of Nigeria, registration number RC 9229333, with its registered office at Enugu, Nigeria.
For all personal information described in this Policy, Ezysphere Limited is the data controller (the entity that decides why and how your information is processed), except where a third-party platform acts as an independent controller in its own right - see section 9.
Our contact point for all privacy matters, including requests to exercise your rights, is apps@ezysphere.com. We have not appointed a Data Protection Officer, as we are not required to do so; privacy requests are handled directly by the people who build and maintain the products.
2. Scope of this Policy
This Policy applies to:
- the website at ezysphere.com and every page on it;
- every mobile, desktop and web application published by Ezysphere, including Build Estimate, EzyNotify, EzyPlayer, ShareOps, AI Trivia, Grid Shooter, Snap Pattern and Assist Scholar (each, an "App"); and
- any email, form or support conversation you have with us.
App-specific supplements
Individual Apps do different things with different data, so several have their own privacy supplement that adds detail on top of this Policy. A supplement never gives you fewer rights than this Policy does; it only describes that App's processing more precisely. Where a supplement and this Policy genuinely conflict, the supplement prevails for that App only. Where an App has no supplement, this Policy applies in full and on its own.
Every supplement is listed on our legal index.
3. Information we collect
3.1 Information you give us
| Category | Examples | When |
|---|---|---|
| Account information | Email address, a password stored only as a salted hash by our authentication provider, display name | Only if you choose to create an account. Most Apps work signed out. |
| Profile and preference information | Country, currency, units, degree level or field of study, notification settings, theme | When you set them up in an App |
| Content you create or upload | Saved estimates, calculations, bookmarks, checklists, watch terms, photographs, documents, files you transfer | When you use the relevant feature |
| Correspondence | Your name, email address and the message you send us through a form or by email | When you contact us or submit a deletion request |
| Payment context | Amount, currency, payment reference, status and the points or subscription it relates to | When you buy something. We never receive or store your card number, CVV or bank credentials. |
3.2 Information collected automatically
| Category | Examples | Notes |
|---|---|---|
| Device and technical data | Device model, operating system version, App version, language, coarse region, crash and error diagnostics | Used to keep the App working on real devices and to fix faults |
| Advertising identifiers | Google Advertising ID, or the iOS Identifier for Advertisers where you have permitted it | Only in Apps that show ads - see section 7 |
| Usage events | Which feature was opened, points earned or spent, streaks, sync timestamps | Held against your account or device so the feature works and balances reconcile |
| Server logs | IP address, timestamp, endpoint requested, response status, user agent | Generated by our hosting and backend providers for security, abuse prevention and rate limiting |
Ezysphere does not run a general-purpose analytics or advertising tracker on the ezysphere.com website. The website sets no cookies of its own - see section 8.
3.3 Information from third parties
- App stores. Google Play, the Apple App Store and the Microsoft Store may give us aggregated, non-identifying install, crash and review data. Purchases you make through a store are confirmed to us by the store.
- Payment providers. Flutterwave and Paystack confirm to us whether a payment succeeded, its reference, amount and currency.
- Authentication providers. If you sign in through a third-party identity provider, we receive the identifiers that provider releases to us.
- Publicly available sources. Assist Scholar aggregates scholarship listings from public web sources. That data is about funding opportunities, not about you.
3.4 Information we deliberately do not collect
- We do not collect precise GPS location in any App.
- We do not read your contacts, call logs, SMS messages or general photo library. Where an App uses the camera or file picker, it receives only the specific item you choose.
- We do not collect government identification numbers, biometric identifiers used to recognise a person, or financial account credentials.
- We do not buy personal information about you from data brokers.
4. Sensitive information
Some Apps necessarily handle material that is personal in nature. We call this out rather than burying it:
- Snap Pattern processes photographs of your body in order to calculate garment measurements. Those photographs are processed transiently and are not retained. Snap Pattern does not perform facial recognition, does not attempt to identify anyone from a photograph, and does not create or store a biometric identifier or biometric template of the kind regulated by laws such as the Illinois Biometric Information Privacy Act. See the Snap Pattern privacy supplement.
- Assist Scholar provides a document vault in which you may choose to store application materials such as transcripts, identity documents and financial statements. Those files are held on your own device by default. See the Assist Scholar privacy supplement.
- Build Estimate transmits floor-plan images you upload to our processing service to generate a bill of quantities. See the Build Estimate privacy supplement.
We do not ask for, and ask that you do not send us, information revealing racial or ethnic origin, political opinions, religious or philosophical beliefs, trade union membership, genetic data, health data, or data concerning sex life or sexual orientation. If you send such information to us unprompted - for example in a free-text support message - we will process it only to answer you and will delete it when the matter is closed.
5. How and why we use your information
- To deliver the feature you asked for - generate an estimate, calculate a measurement, draft a pattern, transfer a file, run a page watch, deliver a reminder.
- To operate accounts and sync - authenticate you, and make your saved data available on your other devices when you sign in.
- To operate points, rewards, streaks, referrals and subscriptions - grant allowances, record spends in a ledger, verify purchases, and prevent double-spending and fraud.
- To take payment - pass the necessary details to a payment provider and record the outcome.
- To keep the products working - diagnose crashes, reproduce faults, monitor capacity and rate-limit abuse.
- To keep the products safe - detect and prevent fraud, abuse of free tiers, referral manipulation, credential stuffing and unauthorised access.
- To communicate with you - answer support requests, send service messages such as security or policy notices, and send notifications you have enabled.
- To show advertising in the Apps that carry it, and to reward you for watching an ad where that is offered.
- To improve what we build - understand which features are used and where they fail, using aggregated or de-identified information wherever that is sufficient.
- To meet legal obligations - keep transaction records for tax and accounting purposes, respond to lawful requests, and establish, exercise or defend legal claims.
We do not sell personal information. We do not rent, trade or otherwise disclose it for another organisation's own marketing. We do not use the content you create in an App - your photographs, documents, files or estimates - to train machine-learning models. We do not build advertising profiles about you from the content of what you upload.
6. Legal bases for processing
Where the EU or UK General Data Protection Regulation applies to you, we rely on the following legal bases. Similar reasoning applies under the Nigeria Data Protection Act 2023.
| Purpose | Legal basis |
|---|---|
| Providing the App and its features; operating your account; taking payment | Performance of a contract with you (GDPR Art. 6(1)(b)) |
| Processing a body photograph in Snap Pattern; enabling optional cloud backup of documents in Assist Scholar; sending optional marketing; personalised advertising; non-essential device identifiers | Your consent (Art. 6(1)(a)), which you may withdraw at any time |
| Security, fraud and abuse prevention; diagnostics and reliability; product improvement using aggregated data; defending legal claims | Our legitimate interests (Art. 6(1)(f)) in running a secure, working, sustainable service - balanced against your rights, and never where those rights override our interest |
| Keeping transaction and tax records; responding to lawful requests from authorities | Legal obligation (Art. 6(1)(c)) |
Where we rely on consent, refusing or withdrawing it costs you nothing except the feature that depends on it, and withdrawal does not affect the lawfulness of processing carried out before you withdrew.
7. Advertising and analytics
Some Apps - currently Build Estimate, AI Trivia and Grid Shooter - show advertising supplied by Google AdMob, including rewarded ads you can choose to watch in exchange for points. Assist Scholar and Snap Pattern carry no advertising.
- AdMob may access an advertising identifier and limited device and ad-interaction data in order to serve, cap, measure and bill for ads. Google acts as an independent controller for some of this processing. See Google's disclosure on how it uses data from sites and apps that use its services.
- In the EEA, the UK and Switzerland, we present a consent message before any non-essential identifier is used for advertising. If you decline, you will still see ads, but they will be non-personalised.
- On iOS, we do not track you across other companies' apps and websites without your permission through the App Tracking Transparency prompt. Declining that prompt does not reduce your access to any feature.
- You can reset or delete your advertising identifier at any time in your device settings, and opt out of ad personalisation there.
We do not operate a third-party analytics SDK for behavioural advertising purposes. Where we use crash reporting or basic usage counters, they exist to keep the App working, not to profile you.
8. Cookies and similar technologies
The ezysphere.com website sets no cookies of its own. It stores nothing in your browser for tracking, and it runs no advertising or analytics scripts. Pages load two third-party static resources - the Google Fonts service and the Cloudflare-hosted cdnjs library used for icons - and submitting a form on the site sends your message to Web3Forms, our form-delivery provider. Those providers necessarily see your IP address and browser user agent as part of serving the request. They are listed in section 9.
Inside the Apps, we use ordinary local storage on your device (for example a preferences file or a local database) to hold your settings and your offline data. That is storage on your own device, not tracking, and it is removed when you uninstall the App.
9. Who we share information with
We share personal information only with the service providers that make the products work, and only to the extent each one needs. Each is bound by a contract or by its own terms to process the data for our purposes, keep it secure, and not use it for its own unrelated ends.
| Provider | What it does for us | Where |
|---|---|---|
| Supabase | Authentication and database for account-based Apps | EU / US regions |
| Google Firebase | Authentication, database, push notifications and crash reporting for Apps that use it | Global (Google Cloud) |
| Google AdMob | Serving and measuring advertising in Apps that carry ads | Global (Google) |
| Flutterwave | Card and bank payment processing (international) | Nigeria / global |
| Paystack | Card and bank payment processing (Nigeria, naira) | Nigeria / global |
| Render | Hosting for the Snap Pattern measurement engine | US / EU regions |
| Google Cloud Run | Hosting for the Assist Scholar watcher service | Global (Google Cloud) |
| Vercel | Hosting and content delivery for ezysphere.com | Global edge network |
| Web3Forms | Delivering website form submissions to our inbox | EU / US |
| Google Fonts, Cloudflare (cdnjs) | Serving fonts and icon files to the website | Global edge networks |
| Google Play, Apple App Store, Microsoft Store | Distributing the Apps and processing store purchases and subscriptions | Global |
| RevenueCat | Managing subscription entitlements and receipts where an App offers subscriptions | US |
We may also disclose personal information:
- to professional advisers such as lawyers, auditors and accountants, under a duty of confidentiality;
- where we are required to do so by law, by a court, or by a competent regulator - and where we are legally free to tell you, we will;
- where necessary to establish, exercise or defend a legal claim, or to protect the rights, property or safety of Ezysphere, our users or the public; and
- to a successor entity in connection with a merger, acquisition or sale of assets, in which case we will require the successor to honour this Policy and will notify you before your information becomes subject to a materially different policy.
This list reflects the providers in use at the date of this Policy. If we add a provider that materially changes how your information is handled, we will update this table and, where required, notify you.
10. International transfers
We are based in Nigeria and our providers operate globally, so your information may be processed outside the country where you live, including in the United States and the European Union.
Where personal information protected by EU or UK data protection law is transferred outside the EEA or the UK, we rely on the European Commission's Standard Contractual Clauses (with the UK International Data Transfer Addendum where applicable), on an adequacy decision, or on another lawful transfer mechanism, together with the technical measures described in section 12. Where the Nigeria Data Protection Act 2023 applies, we transfer personal data only on a basis permitted by section 41 of that Act.
You may request a copy of the relevant transfer safeguards by writing to apps@ezysphere.com.
11. How long we keep information
We keep personal information only as long as we need it for the purpose we collected it for, or as long as the law requires - whichever is longer. In practice:
| Information | Retention |
|---|---|
| Account and profile data | For as long as your account is active, then deleted within 30 days of a verified deletion request |
| Content you create in an App (estimates, bookmarks, checklists, measurements, patterns) | Until you delete it, or until your account is deleted |
| Images sent for processing (floor plans, body photographs) | Held only for the life of the request and discarded when the result is returned. Not stored. |
| Points ledger entries | For as long as the account exists, so balances can be reconciled and disputes answered; deleted with the account |
| Payment and transaction records | Up to 7 years from the transaction, to meet tax, accounting and anti-money-laundering obligations, then deleted |
| Support correspondence | Up to 24 months after the matter is closed |
| Server and security logs | Typically 30 to 90 days, depending on the provider, unless retained longer for an active security investigation |
| Aggregated or de-identified statistics that cannot be linked back to you | May be retained indefinitely |
| Records of a deletion request itself | Retained as proof that we honoured the request, minimised to the request, its date and its outcome |
Backups are overwritten on a rolling cycle. Where data has been deleted from live systems but still exists in a backup, it is isolated from further active use and is removed when that backup expires.
12. How we protect information
- All traffic between the Apps, the website and our services is encrypted in transit using TLS.
- Data at rest with our infrastructure providers is encrypted using their platform encryption.
- Passwords are never stored in a readable form; our authentication provider stores only a salted hash.
- Access to production data is limited to the people who need it, and is authenticated.
- Where an App gates paid content, the gate is enforced on the server or in the database - not in the client - so it cannot be bypassed by modifying the App.
- Payment card details never reach our systems; they are entered with, and held by, the payment provider.
- We apply security updates to our dependencies and infrastructure as part of normal maintenance.
No method of transmission over the internet and no method of electronic storage is completely secure. We use appropriate technical and organisational measures, but we cannot and do not guarantee absolute security. You are responsible for keeping your own account credentials and your own device secure, and for the security of any file you choose to share out of an App.
13. Your rights
Wherever you live, and regardless of whether a particular statute applies to you, we will honour the following requests about your own personal information:
- Access - a copy of the personal information we hold about you, and an explanation of what we do with it.
- Correction - have inaccurate or incomplete information put right.
- Deletion - have your information erased, subject only to records we are legally required to keep.
- Portability - receive the information you gave us in a structured, commonly used, machine-readable format.
- Restriction - ask us to pause processing while a dispute about accuracy or lawfulness is resolved.
- Objection - object to processing based on our legitimate interests, and to any direct marketing, at any time and absolutely.
- Withdraw consent - where processing is based on consent, withdraw it at any time.
- Non-discrimination - exercising any of these rights will never degrade your service, raise your price or reduce your features.
How to exercise them
Use our data request page, or email apps@ezysphere.com stating which App and which right. We will:
- Acknowledge your request promptly;
- Verify that the request comes from you - usually by confirming control of the account email address. We ask for the minimum needed to verify, and use it for nothing else;
- Respond within 30 days. If a request is unusually complex we may extend this by a further period permitted by the applicable law and will tell you why; and
- Charge nothing, unless a request is manifestly unfounded or repetitive, in which case we may charge a reasonable fee or decline, and will explain why.
An authorised agent may make a request on your behalf where the applicable law allows it, provided they supply proof of authorisation.
14. Region-specific rights
14.1 Nigeria
We process personal data in accordance with the Nigeria Data Protection Act 2023 and the Nigeria Data Protection Regulation. You have the rights set out in section 13 above, and the right to lodge a complaint with the Nigeria Data Protection Commission (NDPC).
14.2 European Economic Area, United Kingdom and Switzerland
You have the rights described in section 13 as they are set out in Articles 15 to 22 of the GDPR and the UK GDPR. You also have the right to lodge a complaint with your national supervisory authority - in the UK, the Information Commissioner's Office - although we would appreciate the chance to resolve the matter first.
We have not appointed an EU or UK representative under Article 27, as our processing does not meet the threshold that requires one. If that changes, we will name a representative here.
14.3 California
Under the California Consumer Privacy Act as amended by the CPRA, California residents have the right to know, delete and correct personal information, to opt out of its sale or sharing, to limit the use of sensitive personal information, and not to be discriminated against for exercising those rights.
- We do not sell personal information, and we have not sold personal information in the preceding twelve months. We do not sell the personal information of anyone we know to be under 16.
- Sharing for cross-context behavioural advertising. In Apps that carry AdMob advertising, the use of an advertising identifier to serve personalised ads may constitute "sharing" under the CPRA. You can opt out at any time by declining ad personalisation in your device settings, by declining the App Tracking Transparency prompt on iOS, or by emailing us - and doing so will not change your access to any feature.
- Sensitive personal information. We do not use or disclose sensitive personal information for purposes other than those permitted without a right to limit under the CPRA.
- The categories of personal information we collect, the purposes, the categories of recipients and the retention periods are set out in sections 3, 5, 9 and 11 above. This section, read with those, is our notice at collection.
14.4 Other United States states
If you live in a state with a comprehensive consumer privacy law - including Virginia, Colorado, Connecticut, Utah, Texas, Oregon and Montana - you have rights to access, correct, delete and obtain a copy of your personal data, and to opt out of targeted advertising, sale and certain profiling. We do not sell personal data or engage in profiling that produces legal or similarly significant effects. You may appeal a refusal of a request by replying to our decision; we will respond to an appeal within the period your state's law allows.
15. Children and young people
Our Apps are not directed to children, and the minimum age to use them is set out in our Terms of Service. In summary:
- You must be at least 13 to use an Ezysphere App, and at least 16 if you are in the EEA or the UK, unless a parent or guardian consents on your behalf where the law allows.
- Assist Scholar is aimed in part at secondary-school students. If you are under 18, you may use it only with the consent and involvement of a parent or guardian, and you should not upload identity or financial documents without their agreement.
- Snap Pattern is restricted to adults aged 18 or over, and its Terms prohibit photographing anyone other than yourself.
We do not knowingly collect personal information from a child below the applicable minimum age. If you believe a child has provided us with personal information, contact apps@ezysphere.com and we will delete it and close the account promptly.
16. Automated decisions and profiling
We do not make decisions producing legal effects concerning you, or similarly significantly affecting you, based solely on automated processing.
Some Apps compute things automatically - a match score against your stated study preferences, a bill of quantities from a floor plan, a set of measurements from a photograph. These are informational outputs that you review and act on yourself. They are estimates, they can be wrong, and nothing about you is decided by them. Automated checks are also used to detect fraud and abuse; if such a check restricts your account, you can ask a person to review it by emailing us.
17. Security incidents
If a personal data breach occurs that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority - including the NDPC where Nigerian law applies - within the period required by law, generally 72 hours of becoming aware of it. Where the breach is likely to result in a high risk to you, we will notify you directly and without undue delay, describing what happened, what it means for you, and what we are doing about it.
18. Third-party sites and services
Our website and Apps link out to third-party destinations - app stores, payment pages, and in Assist Scholar the official websites of scholarship providers. We do not control those destinations and are not responsible for their content or their privacy practices. Once you leave our website or App, this Policy no longer applies. Read the policy of any site you land on.
19. Store privacy disclosures
The Data Safety section on Google Play and the Privacy Nutrition Labels on the Apple App Store summarise each App's data practices in the format those stores require. Those summaries are prepared from this Policy and the relevant App supplement. Where a store summary is necessarily compressed, this Policy and the App's supplement are the authoritative statement of what we do.
20. Changes to this Policy
We may update this Policy as our products and the law change. When we do:
- we will change the "Last updated" date and increment the version number at the top of this page;
- for material changes - a new category of data, a new purpose, a new class of recipient, or a reduction in your rights - we will give reasonable advance notice in the App or by email to the address on your account before the change takes effect; and
- where a change requires your consent under applicable law, we will ask for it rather than assume it.
Continuing to use the website or an App after a non-material change takes effect means the updated Policy applies to you. Previous versions are available on request.
21. Complaints
If you are unhappy with how we have handled your personal information or a request, write to apps@ezysphere.com with "Privacy complaint" in the subject line. We will investigate and reply within 30 days. If you remain unsatisfied you may complain to the Nigeria Data Protection Commission, to your national supervisory authority in the EEA, to the Information Commissioner's Office in the UK, or to your state Attorney General in the United States. Nothing in this Policy limits your right to do so.
22. How to contact us
Ezysphere Limited
Registered in the Federal Republic of Nigeria, RC 9229333
Enugu, Nigeria
Email: apps@ezysphere.com
Web: ezysphere.com