EZData Privacy Policy
EZData Privacy Policy
EZData is a data management and display client for the M5Stack / ESP32 device ecosystem. We value your privacy and the protection of your personal information. This Privacy Policy explains how we collect, use, store, share, and protect information when you use the EZData app, home screen widgets, system share extensions, QR code scanning, Bluetooth provisioning, real-time subscriptions, file uploads, and data sharing features.
Please read and understand this Privacy Policy before using the app. If you do not agree with any part of this Privacy Policy, you may stop using the relevant feature or stop using the app. If you deny certain permissions or decline to provide certain information, some features may not work properly.
1. Scope
This Privacy Policy applies to the EZData mobile app and related features, including account sign-in, cloud data management, real-time data subscriptions, device binding, groups and favorites, history records, home screen widgets, system share intake, file viewing and saving, QR code scanning, ESP32 Bluetooth provisioning, and Playground logic orchestration.
This Privacy Policy does not apply to third-party websites, community pages, operating system services, device vendor services, or third-party SDK services that you may access through EZData. Those services process information under their own privacy policies.
2. Information We Collect
2.1 Account and Sign-In Information
- Email address, username or nickname, avatar, and other account profile information.
- Password, authentication token, sign-in status, and other credential information. To support sign-in, session persistence, WebSocket reconnection, widgets, and share extensions, credentials may be stored in local device storage or in an App Group shared container.
- The registration entry may open an M5Stack Community page. Information that you submit on that page is processed by the corresponding community service.
2.2 Device and IoT Data
- Device token, device name, device type, MAC address, or device identifiers provided through QR codes, shared links, or deep links.
- Data token, data name, data type, data value, permission settings, references, subscriptions, sorting, groups, favorites, share records, export records, and history records.
- Device status, data updates, offline alerts, system notices, and other messages generated or received during real-time subscriptions.
2.3 Content You Create, Import, or Share
- Groups, data items, Application data, Global data, Playground projects, logic configurations, widget configurations, and theme configurations that you create or edit.
- Text, images, videos, audio, files, file names, MIME types, file sizes, and temporary cache paths that you select, upload, save, open, or import through the system share sheet.
- Shared links, QR codes, import links,
ezdata://deep links, and parameters carried by those links.
2.4 Device and Environment Information
- Device brand, model, operating system name, operating system version, push notification token, or device vendor push registration ID, used for notifications, offline alerts, configuration synchronization, and device list management.
- Network connection status, current Wi-Fi name, and ESP device names discovered over Bluetooth, used for network recovery, BLE provisioning, and device connection.
- Language, theme mode, notification preference, guide page display state, file cache metadata, and other local preferences.
2.5 Clipboard Information
- When the app returns to the foreground, EZData may read clipboard text to recognize EZData share links, device binding links, or Playground import content.
- To avoid duplicate processing, the app may locally remember the last clipboard text it read. Unless you confirm an import, binding, or open action, we do not proactively upload the full clipboard content to our servers.
2.6 Logs and Error Information
To troubleshoot connection, upload, download, widget update, and provisioning issues, the app may record request status, error information, API response status, file download progress, and similar operational information in local or development debug logs.
3. How We Use Information
- To provide account registration, sign-in, identity verification, session persistence, sign-out, and expired-session handling.
- To display, create, edit, delete, synchronize, subscribe to, share, export, and restore device data, group data, application data, favorites, and history records.
- To receive device data updates, system messages, offline alerts, and subscription messages through HTTP APIs and WebSocket real-time channels.
- To allow home screen widgets to fetch, display, refresh, and update data; and to allow the iOS Share Extension, Android Share Target, and widgets to read necessary configuration and tokens from local shared storage.
- To support QR code scanning, deep links, clipboard link recognition, and system share imports for binding devices, importing groups, or opening specific data.
- To support ESP32 Bluetooth provisioning, including BLE scanning, connecting to a device, reading the current Wi-Fi name, and sending the Wi-Fi SSID and password you provide to the target device.
- To send local notifications, remote notifications, or device vendor notifications for data updates, background service disconnection, offline alerts, and system notices.
- To improve stability, security, compatibility, and user experience; troubleshoot issues; prevent misuse; and respond to user feedback.
4. System Permissions
- Network Access: Used for sign-in, data synchronization, file uploads and downloads, WebSocket real-time subscriptions, widget refreshes, and notification-related communication.
- Camera: Used to scan QR codes, device binding codes, and share codes, or to recognize QR codes from photos. If denied, QR code scanning will not be available.
- Photos, Media, Files, and Storage: Used to select images, videos, audio, or files as data content; open and preview files; save images or videos to your photo library; and receive content from the system share sheet. If denied, file selection, saving, or share import features may not be available.
- Bluetooth: Used to scan, connect to, and configure ESP32 / M5Stack devices. If denied, Bluetooth provisioning will not be available.
- Location and Wi-Fi Information: On some Android and iOS versions, the operating system requires location permission to perform BLE scans or read the current Wi-Fi SSID. EZData uses this permission to assist provisioning and does not proactively read or upload your precise geographic location.
- Notifications: Used to show data update reminders, background service disconnection reminders, offline alerts, system notices, and device vendor push notifications. You can disable notifications in system settings or in the app settings.
- Local Network and Bonjour: Used to discover or connect to related services on your local network and to support device communication or network features.
- Clipboard: Used to recognize EZData share links or import content when the app becomes active. You can prevent this feature from triggering by avoiding copying related links or by clearing your clipboard.
- Microphone, Music Library, or Audio-Related Permissions: The current app primarily uses media files for preview and playback. If future versions enable recording, audio import, or music library features, access will occur only after you actively use the relevant feature and grant authorization.
5. How and Where Information Is Stored
- Local Storage: The app may use SharedPreferences, UserDefaults, App Group shared containers, cache directories, or system temporary directories to store sign-in status, tokens, user preferences, widget configurations, data needed by share extensions, clipboard deduplication records, file caches, and file cache metadata.
- Cloud Storage: Data that you create, upload, synchronize, subscribe to, share, or export through EZData may be sent to EZData servers as needed for the relevant feature, including https://ezdata2.m5stack.com/.
- Device-Side Transmission: During ESP32 provisioning, the Wi-Fi SSID and password you enter are sent to the target ESP device through the Bluetooth provisioning process so that the device can connect to the selected Wi-Fi network. The app does not store your Wi-Fi password as account profile information in the EZData cloud.
- Cache Cleanup: Temporary files, downloaded files, images, audio, video, and file preview caches may remain on your device until the system clears them, you delete them manually, you reinstall the app, or a later app version provides a cleanup mechanism.
6. Sharing, Transfer, and Disclosure
We do not sell your personal information to third parties. We share or disclose necessary information only in the following circumstances:
- To provide core features by sending accounts, device data, files, configurations, shared content, and request parameters to EZData backend services.
- To send notifications by submitting necessary push tokens, device identifiers, and notification content to Apple Push Notification service, device vendor push services such as vivo push where applicable, or operating system notification services.
- To complete Bluetooth provisioning by communicating locally with the target ESP device through Espressif ESP Provisioning-related capabilities.
- When you actively share data, groups, files, QR codes, or links, recipients may access the content that you have authorized for sharing. Please set share permissions carefully.
- When disclosure is necessary to comply with applicable laws, regulations, judicial or administrative requests, or to protect the legitimate rights and interests of users, us, or the public.
- In connection with a merger, division, acquisition, asset transfer, or similar transaction. If personal information is transferred, we will require the new holder to continue to be bound by this Privacy Policy or to obtain your consent again.
7. Third-Party SDKs and Services
- Operating system and platform capabilities: Apple, Google, Android, iOS, photo library, file selectors, notifications, Bluetooth, location, Wi-Fi, WebView, URL Launcher, and related platform services.
- Push and notifications: Apple Push Notification service, Android local notification capabilities, vivo push service, and similar services depending on your device and operating system.
- Device provisioning: Espressif ESP Provisioning, used for ESP32 BLE provisioning.
- Media, files, and scanning: camera scanning, image selection, media playback, file opening, QR code generation, file compression, charts, and related open-source or platform plugins.
- Third-party services may process necessary information under their own rules. We use reasonable efforts to select third-party services with appropriate security capabilities and to use them only as needed to provide the relevant features.
8. Retention
- Account information and cloud data are generally retained for as long as your account exists or for as long as necessary to fulfill the purposes described in this Privacy Policy.
- After you delete device data, groups, files, favorites, or configurations, we will delete or anonymize the relevant content according to system rules. Residual copies in backups, logs, or caches may be removed after a reasonable period.
- Local sign-in status, tokens, preferences, widget configurations, and caches may remain on your device until you sign out, clear app data, uninstall the app, the system clears them, or an app feature actively clears them.
- If a longer retention period is required by law or is necessary for dispute resolution, security audits, or troubleshooting, we may retain information for the necessary period and scope.
9. Your Rights and Choices
- Access and Correction: You can view or modify data, groups, favorites, share permissions, widget configurations, and certain account display information that you create in the app.
- Deletion: You can delete device data, group data, favorites, shared content, or local caches. To request deletion of your account or cloud account profile information, contact us using the information in this Privacy Policy.
- Withdrawing Authorization: You can disable camera, photo library, files, Bluetooth, location, notifications, and similar permissions in system settings, or disable message notifications in the app settings. Withdrawing authorization does not affect processing that was completed based on prior authorization.
- Sign-Out: You can sign out in the app settings. Signing out invalidates or clears certain sign-in states, but some preferences, caches, or historical input may remain on the device. You can delete them by clearing app data in system settings or uninstalling the app.
- Export and Sharing Controls: You can use the export and sharing features provided by the app, adjust share permissions, or stop sharing. Please share data links or QR codes only with trusted recipients.
- Complaints and Feedback: If you have questions, complaints, or rights requests regarding our processing of personal information, contact us at support@m5stack.com.
10. Information Security
- We take reasonable technical and organizational measures to protect your information, including account authentication, token-based access control, permission controls, local storage isolation, operating system permission controls, and appropriate server-side security measures.
- No method of Internet transmission or electronic storage can be guaranteed to be completely secure. Please protect your account, password, devices, share links, QR codes, and any endpoint that can access your data. Do not enter or share sensitive information in untrusted environments.
- If a personal information security incident may affect your rights or interests, we will take remedial measures as required by applicable law and notify you through the app, email, public notice, or another reasonable method.
11. Children's Privacy
EZData is primarily intended for developers, device users, and IoT data management scenarios. It is not directed to children. Minors should use the app only with the consent and guidance of a parent or guardian. If you are under 14 years old, please use the app only with clear consent from your guardian. If a guardian believes that a child's personal information has been improperly submitted to us, please contact us so that we can handle the request.
12. Updates to This Privacy Policy
We may update this Privacy Policy based on product features, legal requirements, or operational needs. After an update, we will publish the new version in the app, on our website, on an app store page, or in another reasonable location, and we will indicate the effective date. If an update materially changes the purposes, methods, or scope of personal information processing, we will provide prominent notice as required by applicable law and obtain your consent again when necessary.
13. Contact Us
If you have any questions about this Privacy Policy, our personal information processing practices, or account data deletion, please contact us through the following channels:
- Email: dev@m5stack.com
- Website: https://m5stack.com/
- EZData service domain: https://ezdata.m5stack.com/