Privacy Policy
Effective date: June 2, 2026
1. Who we are
Echo is a social network built on the principle that your attention is yours. Echo does not sell advertising, does not build third-party tracking profiles, and does not monetize your personal data. This policy describes the information Echo collects, why it collects it, and how you can control it.
2. Information we collect
Information you provide directly
- Account information — username, email address, password (stored as a bcrypt hash, never in plain text), display name, bio, pronouns, and timezone.
- Content — posts, comments, reactions, direct messages, voice notes, poll responses, and files you upload.
- Circle activity — circles you create or join, topics, events, and RSVPs.
- Payment information — if you subscribe to Echo+ or send tips, payment is processed by Stripe. Echo stores only a Stripe customer ID and subscription status; full card details are never stored on Echo servers.
Information collected automatically
- Log data — IP address, browser type, operating system, and request timestamps for security and abuse-prevention purposes.
- Session data — JWT tokens stored in your browser's local storage to keep you signed in.
- First-party analytics — aggregated, non-identifying usage counts (e.g. total posts created per day). No individual user is tracked. No third-party analytics scripts are loaded.
Information we do NOT collect
- Advertising identifiers (IDFA, GAID, or web equivalents)
- Cross-site or cross-app tracking data
- Data from third-party brokers or data exchanges
- Inferred sensitive attributes (race, religion, health, political views)
3. End-to-end encrypted messages
Direct messages between two users are encrypted end-to-end using a Signal-protocol-inspired X3DH key agreement. Echo's servers store only ciphertext and public key material. Echo cannot read the content of encrypted messages. AI features (summarization, assistant) are automatically disabled for encrypted conversations.
4. How we use your information
- Operate, maintain, and improve Echo's features and infrastructure.
- Authenticate your identity and protect your account from unauthorized access.
- Deliver notifications you have subscribed to.
- Process subscription payments and tip transactions through Stripe.
- Respond to abuse reports and enforce the Echo community guidelines.
- Generate the transparency reports published quarterly on this platform.
- Comply with applicable law.
Echo does not use your data to serve advertisements, to train commercial AI models, or to share with data brokers.
5. AI features
All AI features — feed suggestions, catch-up digests, content summaries, topic detection, AI chat, and circle AI — are off by default. You can enable or disable each feature individually in Settings → AI Preferences. When AI features process your content, requests may be sent to third-party AI providers (OpenAI, Anthropic, etc.) subject to those providers' data processing agreements. Content from encrypted messages is never sent to AI providers.
6. Sharing with third parties
Echo shares your data with third parties only in the following limited circumstances:
- Service providers — hosting, database, and CDN infrastructure necessary to run Echo. These providers are contractually prohibited from using your data for their own purposes.
- Payment processor — Stripe processes payment card data under their own privacy policy.
- AI providers — only when you have opted in to specific AI features, and only the minimum content needed to fulfill that feature.
- Legal obligations — if required by a valid court order or applicable law. Echo will notify you of such requests where legally permitted.
Echo does not sell, rent, or trade your personal data.
7. Data retention
Your data is retained as long as your account is active. When you delete your account, Echo begins a 30-day grace period during which deletion can be cancelled. After the grace period, your account, posts, and personal data are permanently deleted from Echo's systems. Message content in conversations you participated in is anonymized (sender removed, content blanked) rather than deleted wholesale to preserve conversation continuity for other participants.
8. Your rights
Depending on your jurisdiction, you may have the right to:
- Access your personal data via Settings → Data & Account → Export Data (GDPR-structured JSON export covering 30+ data categories).
- Correct inaccurate information via your profile settings.
- Delete your account and data via Settings → Data & Account → Delete Account.
- Object to certain processing by contacting us at [email protected].
- Portability — your exported data is in open JSON format.
9. Cookies and local storage
Echo uses browser local storage to persist your authentication token and preferences (theme, reduced motion). Echo does not use third-party cookies, advertising cookies, or persistent tracking cookies. The service worker used for PWA offline support caches only Echo's own static assets and API responses.
10. Children's privacy
Echo is not directed at children under the age of 13. If you believe a child under 13 has created an account, please contact us at [email protected] and we will delete the account promptly.
11. Security
Echo applies industry-standard security measures: bcrypt password hashing, JWT-based authentication, HTTPS with HSTS, strict CORS policy, rate limiting on all sensitive endpoints, and regular dependency audits. Despite these measures, no system is perfectly secure. Please use a strong, unique password and enable two-factor authentication.
12. Changes to this policy
Echo will notify users of material changes to this privacy policy via an in-app notification at least 30 days before the changes take effect. Continued use of Echo after the effective date constitutes acceptance of the updated policy.
13. Contact
Questions about this policy or your data can be directed to [email protected].