Privacy Policy
Last updated July 2, 2026
This Privacy Policy explains how Koi Fish Labs Inc. ("we," "us," or "our") handles information in connection with the Eizo macOS app, the eizo.dev website, and the api.eizo.dev backend (together, the "Service"). It's written to match what the app and backend actually do — not boilerplate.
The short version
Your screen recordings, mouse tracking, and exported videos are created and stored entirely on your Mac. Eizo does not upload them and has no access to them, unless you explicitly submit content to the optional cloud AI generation feature. We don't run analytics or advertising trackers anywhere in the app or on this site, and we don't sell your information.
Information we collect
Local recording data (stays on your device)
When you record with Eizo, the screen capture, mouse-position/click timeline, project
settings, and any exported video are written to ~/Movies/Eizo/ on your Mac. This
data never leaves your device unless you choose to submit it (or content derived from it) to
the AI generation feature described below, or you manually share/upload it yourself.
Account information
Signing in is required only for the AI generation feature and is done via Google or GitHub OAuth — Eizo never sees or stores a password. When you sign in, we receive and store your email address, display name, and profile image as provided by the OAuth provider, along with an internal account identifier. Your session token is stored in your Mac's Keychain and sent as a bearer credential on each request; we don't use cookies for this.
Content you submit for AI generation
If you use the AI video generation feature, the text prompt and any image(s) or reference video(s) you choose to submit are sent to our backend and then to our AI infrastructure subprocessor to produce your output (see "Third parties" below). We don't use this content to train our own models.
Usage and quota data
To enforce fair-use limits and prevent abuse, we store generation job records tied to your account (model used, estimated cost, timestamps, and job status) and rolling usage counters (monthly generation seconds used, per-minute request counts).
Technical data
Our backend logs standard request metadata (IP address, timestamps, endpoint) for security, debugging, and abuse prevention, consistent with typical web server logging.
What we don't collect
- No third-party analytics, advertising, or cross-app tracking SDKs, in the app or on this website.
- No cookies on this website.
- No access to your local recordings, exports, or project files unless you submit them to AI generation.
- No payment information — the Service doesn't currently process payments.
How we use information
- To authenticate you and operate the AI generation feature.
- To enforce usage quotas and rate limits, and to detect and prevent abuse.
- To operate, secure, and debug the Service.
- To respond when you contact us for support.
Third parties we share data with
We rely on a small set of subprocessors to run the Service:
- Google / GitHub — OAuth identity providers used solely to authenticate sign-in.
- Turso — hosts our account, session, and usage database.
- Cloudflare — hosts and serves the api.eizo.dev backend and the eizo.dev website (Workers, CDN, network security).
- Replicate, Inc. — runs the third-party AI model (currently ByteDance's Seedance family) that performs video generation. Prompts, images, and reference videos you submit are processed here to produce your output. Eizo's product surface intentionally doesn't expose this provider's name to keep the API stable if we switch infrastructure — this policy lists it because you're entitled to know.
We do not sell your personal information, and we do not share it with third parties for their own advertising or marketing purposes.
Data retention
- Local recordings and exports are retained on your Mac until you delete them; we have no visibility into or control over them.
- Account data (email, name, profile image) is retained while your account is active.
- Generation job metadata and usage counters are retained to enforce quotas, support billing if introduced, and investigate abuse.
- Generated video output is not stored long-term on our servers — it's streamed through to your device on demand and the provider's underlying URL expires shortly after.
- Reference content you submit for generation (prompts, images, videos) is passed through to our AI subprocessor to fulfill your request and isn't separately retained in our database beyond the job record.
Your choices and rights
You can sign out of Eizo at any time, which removes your session token from the local Keychain. To request access to, correction of, or deletion of your account data, email us at support@koifishlabs.com — we don't yet have a self-serve deletion flow, so account-data deletion requests are handled manually. If you're in a jurisdiction with statutory privacy rights (for example, GDPR or CCPA/CPRA), we'll honor valid requests under those laws.
Children's privacy
The Service is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided us information, contact us and we'll delete it.
Security
Traffic to our backend is encrypted in transit (HTTPS). Session tokens are stored in the
macOS Keychain rather than plain files. Local screen-recording, microphone, and camera access
is gated by macOS's permission system (TCC) and is off until you grant it. Eizo's optional
local automation server (used by the eizo CLI) is disabled by default, binds only
to 127.0.0.1, and requires a locally generated bearer token — it never accepts
connections from outside your machine.
International data transfer
Our subprocessors operate infrastructure in the United States and other countries. By using the Service, you understand that your information may be processed outside your country of residence, subject to appropriate safeguards where required by law.
Changes to this policy
We may update this policy as the Service changes. We'll update the "Last updated" date above; material changes will be reflected here before they take effect.
Contact
Questions about this policy or your data: support@koifishlabs.com.