Echo

Legal

Privacy Policy

What Echo collects, why it collects it, who else processes it, and how to get rid of it.

Last updated 26 July 2026

1The short version

Echo is an AI assistant. To answer you, it has to send what you ask to an AI model. This policy explains what that means for your data.

  • Your conversations are never publicly accessible to others.
  • Invisible Chat is never written to your history. If you report an Invisible Chat response, that report is the one exception: the reported response and the prompt that led to it are saved so we can review the safety concern.
  • We do not sell your personal information.
  • You can delete your account and its data at any time.

2What we collect

Account details.When you sign in with Apple, Google, or an email code, we store the identifier and email address needed to recognise you next time. If you use Apple’s private relay, we only ever see the relay address.

Conversations.Standard chats — your messages and Echo’s responses — are saved to your account so History works. Invisible Chat is not persisted unless you choose to report a response, as described below.

Files you attach. Photos and documents you upload are processed to answer your request. Generated images and sticker packs are stored so they remain available in your library.

Approximate location. Only if you grant permission, and only to answer location questions such as finding places nearby. You can revoke it at any time in iOS Settings; the rest of Echo keeps working.

Safety reports. If you report generated content, we store the selected reason, optional details, the reported response or creation, the prompt that led to it, provider information, and app version. This is necessary to review and resolve the report. For Invisible Chat, submitting a report is your choice to save that otherwise temporary exchange for this limited purpose.

Diagnostics. Basic technical logs — timestamps, error codes, coarse device and app version — used to keep the service running and to investigate faults.

Product analytics. Echo records limited interaction events such as onboarding progress, paywall actions, messages or tools being used, and whether an operation succeeded. These events may be linked to your Echo account so we can understand reliability and improve the product. They never include your prompt or generated content, attachment names, email address, name, precise location, or authentication credentials.

Advertising measurement.If you allow tracking through Apple’s permission prompt, Echo and its measurement providers collect advertising and device identifiers, IP-derived device metadata, app-install and app-open activity, and subscription lifecycle events. We do not send your conversations, email address, or phone number for this purpose.

3How we use it

We use the information above to:

  • Answer your requests and generate the content you ask for.
  • Keep your history and library available across sessions.
  • Operate subscriptions and entitlements.
  • Measure which ads lead to installs, trials, subscriptions, and renewals, but only after you allow tracking.
  • Detect abuse, enforce usage limits, and keep Echo secure.
  • Review reports about harmful or objectionable generated content.
  • Diagnose faults and improve reliability.
  • Understand aggregate onboarding, subscription, chat, and tool usage without recording the content you create.

We do not sell your personal information, and we do not use the content of your conversations to advertise to you.

4AI model providers

Echo is an aggregator. To answer you, the content of your request — including any photo or document you attach — is sent to the AI provider behind the model you selected: OpenAI for GPT, Anthropic for Claude, Google for Gemini, or xAI for Grok. Multi-model requests are sent to each provider you select. Those providers process the request under their own terms and privacy policies to return a response.

If a selected provider is unavailable before it begins responding, Echo may use OpenAI as a fallback. We disclose this before the first AI request and ask for your explicit permission before sending messages, images, or files to any of these providers. We use commercial API tiers, which generally do not train foundation models on submitted content, but each provider’s own policy governs its handling.

Invisible Chat still goes to a model providerin order to produce an answer. What it does is guarantee the exchange is not written to your Echo history. If you submit a report, the reported exchange is stored in Echo’s safety-report queue.

5Who else processes data

We share data with service providers that run Echo on our behalf, under contracts limiting them to that purpose:

  • Cloud hosting and managed database providers.
  • Authentication and account infrastructure.
  • AI model providers, as described above.
  • Apple, for subscription purchases and receipt validation.
  • RevenueCat, for subscription management, entitlement validation, and consented advertising attribution.
  • Meta, for consented app-install, app-open, trial, subscription, and renewal measurement.
  • PostHog, for first-party product analytics. Session replay, automatic screen recording, and element autocapture are disabled.

We may also disclose information where required by law, or to protect the rights and safety of users and the public.

6How long we keep it

Conversations, generated images, and sticker packs are kept until you delete them or delete your account. Safety reports are kept while pending and as needed to document their review, unless you delete your account. Invisible Chat is otherwise not stored. Diagnostic logs are kept for a limited period and then discarded.

When you delete your account we remove your personal data from our production systems and submit deletion of the person profile tied to your Echo user ID to PostHog. We retain only an unlinked aggregate count of account deletions. Residual copies may persist briefly in encrypted backups before being overwritten on their normal cycle. See Delete your data for the exact steps and what each one removes.

7Your choices and rights

  • Delete individual chats or images from History at any time.
  • Use Invisible Chat when you would rather an exchange leave no trace.
  • Revoke location or photo access in iOS Settings.
  • Change tracking permission in iOS Settings. Echo remains fully usable if you decline tracking.
  • Review or withdraw AI data-sharing permissionfrom Account → Privacy & data. Your Echo Plus subscription remains active after withdrawal, but Echo cannot create new AI responses until you allow processing again.
  • Delete your account and its associated data from within the app.

Depending on where you live, you may also have rights to access, correct, export, or object to processing of your personal data. Email contact@echoplus.app and we will respond within the period required by applicable law.

8Children

Echo is not directed at anyone under 16, and we do not knowingly collect their personal information. If you believe someone under 16 has provided us data, contact us and we will delete it.

9International transfers

Echo is operated from, and uses providers located in, countries that may differ from where you live. Where required, we rely on appropriate safeguards for those transfers.

10Changes and contact

We will update this policy as Echo changes, and will give notice in the app or by email if a change is material.

Echo is the controller of the personal data described here. Questions or requests: email contact@echoplus.app or use the contact page. See also our Terms of Service.