Privacy Policy
Last updated September 11, 2026
The short version
Almost every tool on this site processes your files entirely in your own browser — nothing is uploaded to a server. We don't sell data, we don't run tracking pixels, and we don't build a profile of you. A handful of features genuinely need a server (a short link that has to resolve from anywhere, a public link-in-bio page, saving a template to your account, an AI assistant you've explicitly connected) — those are called out explicitly below and on the tool page itself.
Who's responsible for this data
Work Easy is the data controller for the personal data described on this page. For any question or request about your data — including the rights listed below — contact hello@ziptest.app. We aim to respond to any request within 30 days, as required by GDPR.
Client-side tools: your files never leave your device
Tools in PDF, Images, and most of Creator — merging, splitting, compressing, converting, cropping, resizing, watermarking, removing metadata, background removal, QR code generation, and so on — run using your browser's own processing (Canvas, WebAssembly, and libraries like pdf-lib and pdf.js) entirely on your device. The file you upload is read into memory in your browser, processed there, and the result is handed back to you for download. We never see it, store it, or have a copy to lose.
Every tool page that works this way carries a "Processed in your browser" notice. If a tool ever needs to send data to a server, that notice says so instead, plainly.
The anonymous usage check
Tools are free to use without an account, up to a small number of actions per day. To enforce that fairly (and keep the free tier usable for everyone, not exhausted by automated abuse), each action makes a small request to check and update your remaining count. That request sends:
- Which tool you used (e.g. "compress-image") — not the file, not its contents.
- A non-identifying device signal (your browser language, screen size, timezone offset, and a random id stored in your browser) combined with your IP address, immediately hashed into a single one-way value. We never store your raw IP address.
That hash maps to a single counter — how many actions you've used since your count last reset. There's no history kept: the counter is overwritten in place every time it's checked, not appended to a growing log, and it resets automatically every 24 hours. If you sign in, this check is skipped entirely — signed-in accounts have no daily cap.
Legal basis: our legitimate interest in keeping the free tier usable and preventing automated abuse — the data collected is minimized specifically so this doesn't require identifying you personally.
If you create an account
Signing in uses Supabase Auth; we store your email address and the standard authentication records that requires. Beyond that, we only store what you explicitly create: short links you make, a link-in-bio page, saved email templates, your favourited and recently-used tools. Each of these is scoped to your account with database-level access rules — only you can read, edit, or delete your own data, enforced by the database itself, not just application code.
A short link's destination URL and click count are visible to anyone who resolves that link, by design — that's how a redirect works. A link-in-bio page is public at its own URL, again by design, since the whole point is for other people to see it. Your account's internal user id is never included in either of those public views.
Legal basis: performance of a contract — this is the data needed to provide the account features you've asked to use.
Connecting an AI assistant
Signed-in users can optionally connect an external AI assistant (a "GPT," Claude, or any other MCP-compatible client) to their account, using the same OAuth sign-in flow as signing into the site itself — we never see or store your assistant's own credentials, and it never sees your Work Easy password. Once connected, the assistant can read and manage only your own data (favourites, recently-used tools, and short links you've created) — the same database access rules that scope every other feature to your account apply here too, enforced by the database, not the assistant's good behaviour. The assistant never receives your files or their contents; the client-side tools it can point you to still process files entirely in your browser, unchanged.
You can revoke this access at any time from your AI assistant's own connection settings, or by signing out and back in to Work Easy, which invalidates the underlying session.
Cookies and local storage
We use your browser's local storage for things like remembering your theme preference and the random device id used in the anonymous usage check above — not for tracking across other sites. Signing in uses standard session storage to keep you logged in. These are strictly necessary for the site to function, so — unlike the advertising cookies described below — they don't require your consent under GDPR/ePrivacy rules.
Advertising
Some pages show a Google AdSense ad. That space stays a plain placeholder until you answer the ad-preferences prompt shown on your first visit — no ad network script runs and no advertising cookie is set before you choose. Pick "Accept" and you'll see personalized ads; pick "Non-personalized only" and ads may still appear, but AdSense is told to skip personalization and cross-site tracking cookies for you. You can change your choice at any time by clearing this site's data in your browser, which brings the prompt back.
Data retention
Anonymous usage-check hashes: overwritten in place, no history, reset every 24 hours (see above). Account data: kept for as long as your account exists, then deleted within 30 days of account deletion. Anything you create yourself (short links, a link-in-bio page, saved templates, favourites) is kept until you delete it or delete your account, whichever comes first.
International data transfers
Our infrastructure providers (Supabase for authentication and the database; Google, if AdSense is ever turned on) may process data outside the European Economic Area. Where that happens, we rely on the safeguards those providers make available for this — typically the EU Standard Contractual Clauses — as part of using their services.
Your rights under GDPR
If you're in the EEA, UK, or anywhere GDPR-equivalent protections apply, you have the right to:
- Access the personal data we hold about you.
- Rectify inaccurate or incomplete data.
- Erase your data ("right to be forgotten") — including deleting your account entirely.
- Restrict how we process your data in certain circumstances.
- Port your data to another service, in a structured, commonly-used format.
- Object to processing based on legitimate interest, including the anonymous usage check.
- Withdraw consent at any time, where processing is based on consent (e.g. future advertising cookies).
- Lodge a complaint with your local data protection supervisory authority.
To exercise any of these, email hello@ziptest.app. We don't currently have a fully self-service "delete my account" button in the product — a request by email is handled manually within 30 days.
Changes to this policy
If our practices change in a way that matters, we'll update this page and its "Last updated" date.
Questions about this page? hello@ziptest.app. See also: Privacy, Security, and Terms.