Privacy Policy
Last updated: July 30, 2026
Pullify, LLC, a Delaware limited liability company, doing business as Easel Software Solutions (“Easel,” “we,” “us”) operates the Easel deployment platform at easel.sh and app.easel.sh. This Privacy Policy explains how we collect, use, disclose, and protect personal information when you use our websites, applications, and APIs (the “Services”).
1. Who we are
Easel provides a platform for building, deploying, and serving websites and applications at the edge. Questions about this policy: legal@easel.sh.
Controller / operator: Pullify, LLC d/b/a Easel Software Solutions.
Depending on the context, Easel acts as a data controller (for example, for your account and marketing-site analytics) or as a data processor (for Customer Content and End User traffic on deployments you host with us). Enterprise customers may obtain a Data Processing Agreement (DPA) as described on our DPA page.
2. What Easel does
Easel is a freemium platform-as-a-service: you create an account, connect source code (for example via GitHub), deploy projects, and serve them over our edge network. Paid plans are usage-based; Hobby plans are subject to included limits described on our Pricing page.
3. Information we collect
What we do not collect as a product default: we do not sell personal information; we do not require precise GPS location; we do not use advertising cookies for cross-site behavioral ads on the marketing site.
Account information you provide when signing up or managing a workspace: name, email address, authentication identifiers, profile details you choose to add, and organization or workspace metadata.
Billing and transactional information related to paid plans, including payment-related metadata processed by our payment providers (we do not store full payment card numbers).
Customer Content you submit to the Services: source code, build artifacts, environment configuration you choose to store, deployment logs, and related project data needed to build and serve your applications.
End User information generated when visitors access sites you deploy on Easel: IP address, request headers, approximate location derived from IP, and similar technical data required to deliver, secure, and operate the edge network. You are responsible for your own privacy notices to End Users.
Technical and usage data from your browser, CLI, or API clients: IP address, device and browser type, pages viewed, referrers, timestamps, error and performance logs, and product telemetry needed to operate and secure the Services (for example deploy events, feature usage counters, and diagnostic identifiers associated with your account or workspace).
Support and communications content when you contact us (email, forms, or chat), including attachments you send.
Information you submit to Agent Mode or other in-product AI features (alpha): prompts, instructions, and code or project context you choose to include, plus model responses returned to you.
Information from third parties such as identity providers (for example GitHub OAuth), payment and billing partners, and fraud or abuse signals from those partners.
4. How we use information
To provide, maintain, secure, and improve the Services, including builds, deployments, edge delivery, abuse prevention, and troubleshooting.
To create and administer accounts, process billing and taxes, and send service-related notices (security alerts, invoices, material product or legal updates).
To respond to support requests and communicate about the Services.
To provide Agent Mode and other in-product AI features you choose to use (alpha), by sending necessary prompts and context to AI providers as described below.
To analyze aggregate or de-identified usage so we can improve reliability and developer experience.
To comply with law, enforce our Terms and Acceptable Use Policy, and protect Easel, our users, and the public.
Where required, we send marketing communications with an unsubscribe option. Transactional and security messages are not marketing.
Easel does not use Customer Content from the core hosting product (source code, build artifacts, deployment traffic, or End User request data on your sites) to train third-party generative AI foundation models. “Improve the Services” means operating, securing, and developing the platform using aggregate, de-identified, or operational signals—not licensing Customer Content to train third-party foundation models.
Agent Mode and in-product AI (alpha)
Easel Agent Mode and related in-product AI features are labeled alpha. When you use them, prompts, instructions, and code or project context you choose to include may be sent to AI model routers and model providers (currently via OpenRouter to providers such as Anthropic, OpenAI, or Meta) solely to generate responses for that feature. We do not sell that content, and we do not use it to train Easel’s own foundation models.
Underlying model providers process content under their terms and may have their own retention or training policies depending on the model and API tier selected. We configure providers through OpenRouter for inference; we do not grant those providers a license to train foundation models on your Agent Mode content on Easel’s behalf. See /subprocessors. Do not submit secrets or data you are not permitted to share with those providers.
5. Cookies and similar technologies
We use cookies and similar technologies for authentication, session security, and preferences. Essential cookies are required for signed-in features to work. You can control cookies through your browser settings; blocking essential cookies may break login and dashboard features.
We do not currently use advertising cookies or third-party product-analytics cookies (for example PostHog or Google Analytics) on easel.sh. Server-side product telemetry and security logs are described under technical and usage data above. If we introduce non-essential analytics or advertising cookies, we will update this policy and, where required, obtain consent.
We do not respond to Do Not Track browser signals at this time because there is no consistent industry standard; we will revisit this if standards mature.
| Cookie / technology | Purpose | Duration | How to control |
|---|---|---|---|
| Session / auth cookies | Authenticate you to app.easel.sh and keep your session secure | Session or as set by auth configuration | Sign out or clear site cookies in your browser |
| Preference cookies | Remember UI preferences (for example theme) | Up to 1 year | Clear site cookies in your browser |
6. How we disclose information
We disclose personal information to service providers (subprocessors) that help us host, bill, email, authenticate, observe, and secure the Services, under contracts that limit use to providing services to us. A current list is published at /subprocessors.
We may disclose information to workspace or team administrators when you join a team, and to the extent needed for collaboration on shared projects.
We may disclose information if required by law, legal process, or government request, or to protect rights, safety, and security.
We may transfer information in connection with a merger, acquisition, financing, or sale of assets, subject to appropriate confidentiality protections.
We do not sell personal information as “sale” is commonly defined under US state privacy laws, and we do not share personal information for cross-context behavioral advertising.
7. Subprocessors and third-party services
Infrastructure and service providers process data on our behalf. See /subprocessors for the current list and privacy links. Third-party products you connect (for example GitHub) are governed by their own terms and privacy policies.
8. Data retention
| Category | Retention |
|---|---|
| Account and workspace data | While your account is active; deleted or anonymized within 30 days after account closure, except where law requires longer retention |
| Customer Content (code, deployments, logs) | While projects remain on the platform; made inaccessible on project/account deletion and purged from active systems within 30 days, subject to backup cycles (typically overwritten within 90 days) and legal holds |
| Billing and tax records | As required by tax and accounting law (often up to 7 years) |
| Security and access logs | Typically 30–90 days, longer if needed for an investigation or legal obligation |
| Support tickets and email | Typically up to 24 months after resolution, unless a longer period is needed for an ongoing matter |
| Agent Mode / AI prompts and completions | Up to 30 days for abuse, reliability, and support debugging unless a longer period is required by law; not used to train third-party foundation models as described above |
9. Your privacy rights
Depending on your location, you may have rights to access, correct, delete, or export personal data, object to or restrict certain processing, and withdraw consent where processing is consent-based.
EEA/UK (GDPR): you may have rights of access, rectification, erasure, restriction, portability, and objection, and the right to lodge a complaint with a supervisory authority. We process account and service data where necessary to perform our contract with you, for legitimate interests (security, product improvement using aggregate/de-identified signals) that are not overridden by your rights, or with consent where required.
California (CCPA/CPRA): you may have rights to know, delete, and correct personal information, to opt out of sale or sharing, and to limit use of sensitive personal information where applicable. Easel does not sell personal information, does not share it for cross-context behavioral advertising, and does not use or disclose sensitive personal information for purposes that require a right to limit under CPRA beyond providing the Services. You will not be discriminated against for exercising privacy rights.
To make a request, email legal@easel.sh. We may need to verify your identity. We aim to respond within 30 days (or sooner if law requires).
10. International transfers
Easel and its subprocessors may process data in the United States and other countries. Where we transfer personal data from the EEA, UK, or Switzerland to countries without an adequacy decision, we rely on appropriate safeguards such as Standard Contractual Clauses (and UK equivalents), as applicable. Details for Enterprise customers are addressed in the DPA.
11. Children
The Services are not directed to children under 16. We do not knowingly collect personal information from children under 16. If you believe a child has provided us personal information, contact legal@easel.sh and we will take appropriate steps to delete it.
12. Security
We implement technical and organizational measures designed to protect personal information, including TLS in transit, access controls, and infrastructure security practices. No method of transmission or storage is completely secure; you are responsible for safeguarding your credentials and for configuring deployments securely (including secrets and environment variables).
If we become aware of a breach affecting your personal information, we will notify you and regulators as required by applicable law.
13. Changes
We may update this Privacy Policy from time to time. We will post the updated policy with a new “Last updated” date. Material changes will be communicated in advance where required by law. Continued use of the Services after the effective date constitutes acceptance of the updated policy.
14. Contact
Privacy questions and data subject requests: legal@easel.sh. Support for account issues: support@easel.sh.
Operator: Pullify, LLC d/b/a Easel Software Solutions (Delaware).
EEA/UK supplement
Controller contact: Pullify, LLC d/b/a Easel Software Solutions, legal@easel.sh. Legal bases include contract performance (Art. 6(1)(b)), legitimate interests (Art. 6(1)(f)) for security and product improvement, and consent (Art. 6(1)(a)) where required (for example certain cookies or marketing).
If EU/UK law requires us to appoint an Article 27 representative, we will publish that representative’s contact details on this page.
You may lodge a complaint with your local data protection authority. International transfers rely on SCCs or other lawful mechanisms as described above. Enterprise processor terms are available via our DPA page.
California supplement
Categories of personal information we may collect, sources, and business purposes:
| Category (CPRA) | Examples | Sources | Business purpose |
|---|---|---|---|
| Identifiers | Name, email, IP address, account IDs | You; auth providers; devices | Account, security, billing, support |
| Customer records | Billing contact, plan metadata | You; payment partners | Billing and customer service |
| Commercial information | Plan, purchases, usage meters | You; billing systems | Provide and improve Services |
| Internet / network activity | Logs, telemetry, deploy events | Your use of Services | Security, operations, reliability |
| Professional information | Workspace/org role you provide | You; teammates | Collaboration and admin |
| Inferences | Limited product usage insights | Derived from activity | Improve developer experience |
We disclose personal information to service providers for those business purposes (see /subprocessors). We do not sell personal information or share it for cross-context behavioral advertising. We do not use sensitive personal information for inferring characteristics about you. To exercise California privacy rights, email legal@easel.sh. Authorized agents may submit requests subject to verification.