Privacy Policy
Echoo · Last updated: 2026-08-12 ·
Home ·
Privacy ·
Terms ·
Delete account ·
Delete data
This policy describes how Echoo (“we”, “us”) processes personal data when you use the
Echoo mobile application (the “App”) and our websites or services at
echoo.day (together with the App, the “Services”). Features vary by platform
and settings; only the parts you use apply to you.
Contact
For privacy questions and requests: contact@echoo.day
Account deletion: echoo.day/delete-account.
Data deletion without closing your account: echoo.day/delete-data.
1. Who is responsible?
The controller for personal data processed through the Services is the operator of Echoo.
You can reach us at the contact address above.
2. What we process in the App
Depending on how you use Echoo, this may include:
- Account and profile — email address; display name and username; optional bio, avatar image, and phone number (e.g. for contact matching); authentication data from passwordless sign-in (Magic Link / email OTP) and OAuth (Google and/or Apple), including identifiers those providers share with us to create or link your account.
- Journal content — voice recordings, transcripts, titles, summaries, images, video, collections/lists, and other media or text you save; optional entry location (coordinates and/or place name) and dates you attach; on-device drafts and sync metadata needed to keep your journal available across sessions.
- Social features — friendships and requests; likes, comments, and tagged friends on shared entries; public/visibility settings; friend suggestions preferences; reports and blocks you submit about other users.
- Contacts (optional) — if you grant permission, the App may read device contacts on your device to suggest friends (for example by matching hashed phone numbers or similar identifiers). We do not sell your address book. Matching is used only to power friend discovery you enable.
- AI-assisted features — when you use cloud transcription, titles, or summaries, relevant journal audio/text is sent to our backend and configured AI providers (e.g. OpenAI) to produce results you requested.
- Device permissions and sensors — microphone (recording); camera and photo library (media you attach); approximate/precise location when you choose to add it to an entry; notification permission for reminders and (where enabled) remote push.
- Notifications — local daily reminder schedules stored on your device; remote push tokens and delivery metadata if remote push is enabled for your build and you grant permission.
- Diagnostics and product data — app version, device/OS type, crash and performance signals (e.g. via Sentry). Optional product analytics (e.g. PostHog) only if you opt in; analytics defaults to off in the App.
3. What we process on echoo.day (web)
- Waitlist and email flows — email address and related metadata when you join the waitlist, confirm your address, or use referral or feedback entry points we host on the Site.
- Technical data — data typically sent by your browser (e.g. IP address, user agent, timestamps) when you load pages or call our APIs.
- Optional analytics on the Site — if you accept our cookie/analytics banner, we may use analytics tools to measure traffic and conversions.
4. Purposes and legal bases (GDPR)
- Providing the Services, operating accounts, sync, security, and support — Art. 6(1)(b) GDPR and/or Art. 6(1)(f) GDPR.
- AI processing you request in the App — typically Art. 6(1)(a) GDPR and/or Art. 6(1)(b) GDPR.
- Optional analytics (App or Site) — Art. 6(1)(a) GDPR (consent).
- Legal compliance and enforcement — Art. 6(1)(c) GDPR and/or Art. 6(1)(f) GDPR.
5. Processors and recipients
We use service providers to host and operate the Services. These commonly include
Supabase (authentication, database, storage, edge functions),
Expo (app updates / push infrastructure where used), map/tile providers when you
view maps, and—depending on your choices—PostHog (analytics),
Sentry (crash diagnostics), and AI infrastructure
(e.g. OpenAI) for cloud AI features. OAuth sign-in involves Google and/or
Apple as identity providers. Providers process data on our instructions under
appropriate agreements. Where they process data outside the EEA, we rely on suitable transfer
mechanisms (such as Standard Contractual Clauses) as offered by the provider.
Content you mark public or share with friends is visible to those recipients according to your
settings. We do not sell your personal data.
6. Retention
Journal content and account data are retained until you delete them or close your account,
subject to short backup and legal retention windows (typically up to about 90 days for residual
backups after deletion, unless law requires longer). Waitlist records follow our operational
needs for launch and communication. You can export or delete data in the App as described on
Delete data and Delete account.
7. Your rights
Depending on your location, you may have the right to access, rectify, erase, restrict or object
to certain processing, and to data portability. You may lodge a complaint with a supervisory
authority. Contact
contact@echoo.day or use the in-app tools linked above.
8. Children
The Services are not directed at children under the minimum age required in your country
(typically 16 for the EEA unless local law sets a lower age with consent). Do not use Echoo or
provide personal data if you do not meet that requirement.
9. Changes
We may update this policy from time to time. We will reflect material changes by updating the
“Last updated” date above and, where appropriate, through the App or Site.