Breezell LogoBreezell

Breezell Privacy Policy

Last updated: September 3, 2026

Breezell (“Breezell”, “we”, “us” or “our”) respects and protects your privacy. This Privacy Policy (the “Policy”) explains how we collect, use, store and share your personal information when you use the Breezell editor, your Breezell account, the Breezell website at https://breezell.com and the AI features delivered through them (together, the “Service”), and the rights you have under applicable law — including the EU General Data Protection Regulation (GDPR), the Swiss Federal Act on Data Protection (FADP), the California Consumer Privacy Act as amended by the CPRA (CCPA/CPRA), the China Personal Information Protection Law (PIPL) and other national and regional privacy laws.

Please read this Policy before using the Service. By using the Service you acknowledge that you have read and understood it. We may update this Policy from time to time; material changes are announced in advance as described in Section 13. This Policy forms part of our Terms of Service and is complemented by our Cookie Policy.

1. Data Controller

The controller responsible for personal information processed under this Policy is:

  • Operator: Breezell, operated by the Breezell team
  • Location: Zurich, Switzerland
  • Privacy contact: [email protected]
  • Data Protection Officer (DPO): not appointed — privacy requests are handled by the Breezell team through the contact above

2. Personal Information We Collect

We collect only what is needed to run the Service. Depending on how you use Breezell, this includes:

2.1 Information you provide

  • Account information: email address, display name or username, organization identifier (optional) and your password, which is stored only as a salted hash.
  • Third-party login: if you sign in with GitHub, we receive the basic profile information GitHub is authorized to share (GitHub user ID, username, email address and avatar). We never receive your GitHub password.
  • Payment and plan information: the plan or top-up purchased, transaction amount, currency, payment status, invoice details and transaction identifiers. We do not receive or store full card numbers — card data is handled exclusively by our payment processor (see Section 5).
  • Communications: emails, Telegram or SMS messages, support requests, partnership inquiries submitted through the contact form (name, email, phone and company if you provide them) and any feedback you send us.

2.2 Information collected automatically

  • Device and network data: IP address, operating system, device type, Editor version, browser type, language and time zone.
  • Usage data: which features and modes you use, requests made to AI features (model, mode, token or balance consumption, timestamps), feature performance metrics, session duration and pages visited on the Website.
  • Log and diagnostic data: request timestamps, error and crash reports, and execution logs of Agents, Skills and MCP calls kept for security auditing and abuse prevention.
  • Device fingerprint (fraud prevention): for promotional programs such as invitation rewards we compute a non-personal device fingerprint to detect duplicate or fraudulent claims. It is not used for advertising.

2.3 Your content (controlled processing)

Source code, configuration files, database schemas, prompts and other material you submit to AI features (“Content”) is processed only when you actively trigger an AI action. Content is transmitted to the AI model provider you selected in order to produce a result and is not stored on Breezell’s servers beyond the transient processing needed to serve the request. We never use your Content to train AI models — ours or any third party’s — without your explicit consent. With a Custom API (bring-your-own-key) plan, Content goes directly to the provider whose key you configured. You may also configure local models to keep Content entirely on your device.

We do not knowingly collect special categories of personal data (such as health, biometric or political data) and ask you not to include them in Content.

3. How We Use Your Personal Information

PurposeLegal basis (GDPR / FADP)
Providing, operating and maintaining the Service, including AI-assisted editing, indexing and Agent capabilitiesPerformance of a contract
Account creation, authentication and device-limit enforcementPerformance of a contract
Billing, payment processing, plan and balance management, receiptsPerformance of a contract
Customer support and responding to your inquiriesPerformance of a contract / legitimate interests
Service notices — billing, renewal reminders, security alerts, policy updatesLegitimate interests / legal obligation
Security, fraud and abuse prevention, including audit logs and device fingerprinting for promotionsLegitimate interests
Product improvement and aggregated analyticsLegitimate interests
Compliance with legal obligations, including tax and accounting record-keepingLegal obligation
Marketing communications about Breezell features and promotions (optional)Your consent

We may aggregate or de-identify data for statistical analysis. Such data can no longer identify you and is not personal information.

4. Cookies and Tracking Technologies

The Website and dashboard use cookies and similar technologies as described in our Cookie Policy:

TypePurposeCan be disabled
Strictly necessaryKeeping you signed in, security, load balancing, remembering your consent choiceNo
FunctionalLanguage, region and theme preferencesYes
AnalyticsAggregated, anonymized usage statistics to improve the WebsiteYes
MarketingNot used. We do not run behavioral or targeted advertising

We do not perform cross-site tracking. Where a third-party analytics tool is used, it is configured for anonymized or pseudonymized collection and is named in the Cookie Policy. Fonts on the Website are served by Google Fonts, which receives your IP address when the font files are loaded. You can manage cookies through your browser settings or the consent controls on the Website.

5. Sharing and Disclosure of Personal Information

We do not sell your personal information, including in the sense of “sale” or “sharing” under the CCPA/CPRA, and we do not share it for cross-context behavioral advertising. We share personal information only in the following cases:

  • Payment processor. Purchases are processed by our PCI-DSS compliant payment processor, Waffo Pancake, which acts as merchant of record. Payment card data is handled exclusively by Waffo Pancake and is never stored on Breezell’s servers. We receive only the transaction status, amount and identifiers needed to activate your plan and handle refunds.
  • AI model providers. When you use an AI feature, the Content of that request is sent to the model provider you selected (for example OpenAI, Anthropic, Google, xAI or DeepSeek) under that provider’s data-processing terms, solely to generate the response.
  • Service providers. Cloud hosting, email delivery, error monitoring and support tooling vendors who process data on our behalf under confidentiality and data-processing agreements and only as necessary to deliver the Service.
  • Third-party login. If you sign in with GitHub, GitHub processes the authentication under its own privacy policy.
  • Legal and regulatory requirements. Where required by law, court order or a lawful request from a competent authority, or to protect the rights, property or safety of Breezell, our users or the public.
  • Business transfers. In a merger, acquisition, financing or sale of assets, personal information may be transferred to the successor; we will notify you in advance and the successor remains bound by this Policy.
  • With your consent. For any other purpose you have expressly agreed to.

6. Data Security

  • Encryption in transit: all traffic between the Editor, the Website and our servers uses TLS/HTTPS.
  • Storage security: passwords are salted and hashed; authentication tokens and API keys you store with us are encrypted at rest.
  • Access control: least-privilege access for team members, each bound by confidentiality obligations; administrative actions are logged.
  • Isolation: Content is processed transiently and not written to persistent storage; audit logs contain metadata, not your source code.
  • Monitoring: regular security reviews, dependency and vulnerability scanning.

If a security incident affects your personal information, we will notify you and, where required, the competent supervisory authority within 72 hours of becoming aware of it, in accordance with applicable law. Please keep your account credentials confidential and do not share them with others.

7. Retention of Personal Information

Data typeRetention periodAt expiry
Account informationFor the life of the account, then 90 days after cancellation or deletion requestDeleted or anonymized
Transaction and billing records10 years, as required by Swiss accounting and tax lawArchived, then deleted
Usage and consumption records (model, tokens, timestamps — no Content)12 months, to support billing disputes and refundsDeleted or aggregated
Support communications2 years after the case is closedSecurely deleted
Security and audit logs12 monthsSecurely deleted
Content submitted to AI featuresNot retained beyond transient processing of the requestDiscarded
Device fingerprints for promotionsFor the duration of the promotion plus 12 monthsDeleted

Where a longer period is required by law or is necessary to resolve a dispute, we retain the specific records concerned only for as long as needed for that purpose.

8. Your Data Rights

Subject to applicable law, you have the rights below. To exercise them, contact [email protected] from the email address on your account; we respond within 30 calendar days (extendable where the law allows for complex requests, in which case we tell you).

RightWhat it means
To be informedKnow what data we collect and how we use it — this Policy
AccessReceive a copy of the personal information we hold about you
RectificationCorrect inaccurate or incomplete information; you can edit most account details yourself in the dashboard
ErasureAsk us to delete your data, subject to legal retention obligations (Section 7)
RestrictionAsk us to pause processing in certain circumstances
PortabilityReceive your data in a structured, machine-readable format
ObjectionObject to processing based on legitimate interests or to direct marketing
Withdraw consentWithdraw consent at any time for processing based on consent, without affecting prior processing

If you believe we have not handled your personal information properly, you have the right to lodge a complaint with your local data-protection authority — in Switzerland the Federal Data Protection and Information Commissioner (FDPIC), or the supervisory authority of the EU member state where you live or work. California residents may exercise their CCPA/CPRA rights through the same contact; we do not discriminate against you for exercising them.

9. Marketing Communications and Opt-out

With your consent, we may send you emails, Telegram messages or in-app notices about new Breezell features, promotions and free-token events. You can opt out at any time by clicking the unsubscribe link in any marketing email, turning off marketing notifications in your account settings, or contacting us. Opting out does not affect service notices that are necessary for your account, such as receipts, renewal reminders, security alerts and policy updates.

10. International Data Transfers

Breezell is operated from Switzerland. Our hosting providers, the payment processor and the AI model providers you select may process data in Switzerland, the European Union, the United States and other countries. When personal information is transferred across borders we rely on:

  • the adequacy decisions recognized under Swiss and EU law where the destination country is covered;
  • data-processing agreements incorporating the EU Standard Contractual Clauses (SCCs) with the Swiss addendum, for transfers to other countries;
  • transfer mechanisms required by other applicable laws, including PIPL requirements for data originating in mainland China;
  • transfers only to recipients that provide an equivalent level of protection.

11. Children

The Service is intended for users aged 16 or older; purchases require you to be at least 18 (see the Terms of Service). We do not knowingly collect personal information from children below 16 (or the higher minimum age in your jurisdiction, such as 13 under US COPPA rules where applicable). If you believe a child has provided us with personal information, contact us and we will delete it promptly.

The Service may contain links to, or integrate with, third-party websites and services — including AI model providers, MCP servers you connect, GitHub and community platforms. This Policy applies only to information collected by Breezell. We are not responsible for the privacy practices of third parties and encourage you to read their policies before using them.

13. Changes to This Policy

If we make material changes to this Policy we will notify you at least 15 days before they take effect, by email to your registered address or by a notice on the Website and in the Editor, and we will update the “Last updated” date at the top of this page. Continued use of the Service after the effective date constitutes acceptance of the updated Policy. Previous versions are available on request.

14. Contact Us

Breezell · https://breezell.com