Your data is safe with us.
EzyRing is engineered for security, privacy, and trust at every layer — from your password to the call audio that leaves your browser.
HTTPS Everywhere
Every connection between your browser and ezyring.com is encrypted with TLS. HSTS tells browsers to refuse insecure connections to us.
Bcrypt Password Hashing
Passwords are hashed with bcrypt (cost factor 12) before they ever touch our database. We never see, log, or store your password in plain text.
PCI via Stripe
We never see your card number. All payments are processed by Stripe (PCI Service Provider Level 1, the highest tier). Card data never reaches our servers.
Your Data Rights
We collect only what we need to run the service. You can ask us to access, correct, export or delete your data. Just email privacy@ezyring.com.
Anti-Fraud Rate Limiting
Multi-layer rate limits on auth endpoints (per-IP, per-email, per-account) block credential-stuffing, signup abuse, and password-spray attacks before they hit the database.
No Call Audio Stored
The audio between your browser and Twilio is encrypted with WebRTC (SRTP). We do not record, transcribe, or store the audio content of your calls.
Session Invalidation
Changing your password instantly invalidates every other active session worldwide. Sign in to a new device and old sessions are revoked automatically on critical events.
Verified Caller ID Only
A number can only be your caller ID after a verification call to that phone, and a number verified on one account can't be used by another.
Sign in with Google
OAuth 2.0 with PKCE and state-cookie binding. ID tokens are verified against Google's JWKS on every callback. No password to leak if you sign in with Google.
How your call is protected
When you place a call from EzyRing, here's what happens behind the scenes — all designed to keep your conversation private.
- Your browser establishes a WebRTC connection to Twilio's media servers over SRTP (Secure Real-time Transport Protocol).
- Twilio connects the call to the phone network of the country you're calling. That last leg runs over the regular phone network, which is not end-to-end encrypted, the same as any normal phone call.
- We log only metadata (timestamp, destination, duration, cost) — never the audio.
- Twilio publishes its own security and compliance details in its security overview.
Account security best practices
A few things you can do to keep your EzyRing account even safer:
- Use a unique, strong password not used on any other site. We enforce minimum 8 characters and block known-compromised passwords on signup.
- Prefer Sign in with Google if you already have a strong Google account — it removes the password from the equation entirely.
- Check your call history and wallet transactions now and then, so you spot anything unusual early. Calls are prepaid, so your account can never spend more than its balance.
- Sign out from public computers. Even though sessions are HttpOnly cookies, signing out clears them server-side too.
Where your data lives
The EzyRing app and its database run on our own servers, hosted by OVHcloud in the United Kingdom. Traffic reaches them through Cloudflare, which provides TLS, DNS and a web application firewall. Server backups are kept with OVHcloud. A few specialist providers handle calls, payments, email and chat:
OVHcloud
Server hosting: the EzyRing app, its database and server backups
Cloudflare
DNS, TLS, content delivery and web application firewall in front of ezyring.com
Twilio
Placing your calls and the caller-ID verification call
Stripe
Card payments for credit top-ups, including 3-D Secure and fraud checks
Resend
Sending account and transactional emails (verification, receipts, password resets)
Crisp
Live chat, only after you choose to open it
Sign in with Google (only if you choose it), and Google Analytics 4 (only if you accept analytics cookies)
Full details, including what data each one receives: Sub-processors.
Headers & web hardening
Every response from ezyring.com is served with these security headers:
- Strict-Transport-Security with
preload— browsers refuse HTTP forever after first visit. - Content-Security-Policy — only our own scripts, plus Stripe (payments), Twilio (calling), and Crisp (live chat), can execute.
- X-Frame-Options: DENY — clickjacking protection.
- Referrer-Policy: strict-origin-when-cross-origin — your URL parameters never leak to third parties.
- HttpOnly + Secure + SameSite=Lax cookies — auth tokens cannot be read by JavaScript or sent on cross-site requests.
Responsible disclosure
If you believe you've found a security vulnerability in EzyRing, please email us at security@ezyring.com.
We commit to:
- Acknowledge your report within 48 hours.
- Provide a status update within 5 business days.
- Work with you to validate and reproduce the issue.
- Credit you in the fix release notes (if you wish).
Please do not publicly disclose the issue until we've had a chance to fix it. We don't take legal action against security researchers acting in good faith.
Compliance & transparency
EzyRing operates under EU consumer protection law. Read the details in our:
Last reviewed: October 2026 — Security is a continuous process. We update this page as our practices evolve.