Security and backups

Last updated: October 1, 2026

Your content is the work product of your team and your clients. This page explains where it lives, how it is protected, how long it is kept, and who else touches it.

Hosting and infrastructure

EasyContent runs on Amazon Web Services (AWS) in the United States. The application, its database, and every file you upload are hosted on AWS infrastructure. Uploaded files, including assets, attachments, and images, are stored on Amazon S3, which AWS designs for 99.999999999% durability of stored objects.

Encryption

Your data is encrypted in transit and at rest. Connections to EasyContent are protected with TLS, and data stored in our database, backups, and file storage is encrypted using AWS encryption services. Passwords are stored only as one-way hashes, never in plain text.

Backups and disaster recovery

We take encrypted backups of the database every day and store them on AWS. Backups exist so we can restore the service after an infrastructure failure. They are kept only as long as that restoration window requires and are then overwritten in the ordinary course.

Backups are a disaster recovery tool and cannot be used to restore an individual item. To recover earlier wording of a content item, use its version history.

Version history

Every content item keeps its 30 most recent versions automatically, so you can compare and restore earlier wording at any time. Two limits apply together. The 30-version limit sets how many revisions are kept per item. The history retention period on your plan (1 year on Starter, Studio, and Team; unlimited on Business and Enterprise) sets how long revision data is kept.

Access control

You decide who sees what. Roles and permissions control access at the account, project, and user level, and workflow steps restrict who can edit or approve content at each stage. Review links expose only the item shared, and commenting, editing, or approving through one requires a registered guest account. Single sign-on (SSO) is available on the Business and Enterprise plans.

EasyAI follows the same model. Account owners can turn AI features on or off for the whole account, for specific projects, or for specific team members, and every AI edit is reviewed side by side before it is accepted.

AI processing

When a user runs EasyAI Writer or EasyAI Editor, the relevant text and instructions are sent to our AI model provider, Anthropic, to generate the result. Web research requested through EasyAI Writer runs through Anthropic's search capability. We use LangSmith to monitor the quality and reliability of AI requests. EasyContent does not use your content to train AI models.

Content is sent to AI services only when someone in your account runs an AI feature. If AI is disabled for your account or project, nothing from it is sent.

Payments

All payments are processed by Stripe, a PCI-compliant payment processor. Card details go directly to Stripe and are never stored on EasyContent servers.

Service providers

We use a small number of service providers to run EasyContent. The subprocessors that handle content in your account are listed in Annex III of our Data Processing Agreement.

Provider Purpose Location
Amazon Web Services, Inc. Hosting, database, file storage, backups, transactional email (Amazon SES) United States
Stripe, Inc. Payment processing United States
Anthropic, PBC AI model processing and web search for EasyAI United States
LangChain, Inc. (LangSmith) Monitoring of AI requests United States
Functional Software, Inc. (Sentry) Application error monitoring United States
Google LLC (Google Analytics) Usage analytics United States

We also use Google Workspace for business email and demo calls, Calendly for demo scheduling, and Rewardful for our affiliate program. Our GDPR policy lists the service providers that handle personal data.

We do not sell your personal data or your content. We use your data to provide, secure, and improve the service, as described in our Privacy Policy and GDPR policy.

Data retention and deletion

While your subscription is active, your content, projects, users, templates, files, and settings are kept for as long as you keep them. Project activity logs are deleted after 1 year, and copies of email notifications are deleted 7 days after they are sent.

After an unconverted trial ends, the account is kept for 1 year and then permanently deleted. After a paid subscription ends, the account is kept for 2 years after the last billing period and then permanently deleted, so you can return and pick up where you left off. The full schedule is in our GDPR policy.

You can delete your account at any time with the Delete account button in Account Settings. This permanently deletes the account and all of its data from the EasyContent service immediately, and cannot be undone, so export anything you want to keep first. Copies in our encrypted disaster-recovery backups are removed as those backups are overwritten, billing records are kept as tax and accounting law requires, and logs and diagnostic data held by us and our service providers expire on our and their retention periods, including those set out in our GDPR policy. Content items can be exported to HTML or DOCX. You can also ask us to delete your account by writing to support@easycontent.io.

Monitoring and ongoing practice

We monitor the service continuously, apply security updates on an ongoing basis, and run periodic security audits.

Reporting a security issue

If you believe you have found a security vulnerability in EasyContent, email support@easycontent.io with "Security" in the subject line and enough detail for us to reproduce it. Please give us a reasonable opportunity to fix the issue before disclosing it publicly. We will acknowledge your report and keep you informed as we work on it.

Security reviews and contracts

If your organization runs a security review, we are happy to complete your security questionnaire; email support@easycontent.io. Our Data Processing Agreement, published at easycontent.io/dpa, applies automatically to every customer, and we can provide a countersigned copy on request. On the Enterprise plan, security questionnaires, DPA, and MSA paperwork are handled as part of implementation.