The plain version
Echo does not sell your data or build advertising profiles from it. Echo keeps the source and, when available, visual evidence behind a save so it can show what it understood later. You can ask Echo to delete a save, remove it from a pool, revoke a share, or delete your account.
What Echo receives
Echo receives the messages, links, screenshots, documents, voice notes and videos you send, plus the conversation context needed to answer you and the phone identity needed to maintain the conversation. It also stores the facts, places, dates, prices and visual evidence it derives from a save.
Who helps process a save
Photon carries the Messages conversation. Cloudflare and Convex run Echo’s application, queues and storage. Depending on what you send, Echo may use Firecrawl or ScrapeCreators to open a public link, Amazon Bedrock to understand it, and Google Maps to match a place. A save is only sent to the providers needed to process it.
Echo does not claim end-to-end encryption or zero provider retention. Photon’s public material does not publish a message-specific deletion interval, and other processors retain data under their own service terms and controls. Provider retention and model-training practices follow their published terms and Echo’s account controls.
How long Echo keeps things
- A raw attachment sent directly to Echo is scheduled to expire after six hours.
- Raw retry material for a public social post is scheduled to expire after 24 hours.
- An upload that never becomes a registered save is eligible for deletion after six hours. Cleanup runs hourly.
- Optimized screenshots, video frames, document pages, transcripts and extracted text stay with the memory as evidence until that memory is deleted.
- During alpha, Echo’s inbound conversation text and outbound delivery records remain until account deletion.
Public-source caching
If two people send the same known public social post, Echo may reuse fresh public acquisition work for up to 24 hours. Public source evidence may remain longer while a saved memory still references it. The cache contains no phone number, name, private note, pool membership or permission. Private files, authenticated pages and ordinary webpages are not shared through that cache.
Sharing
Sharing grants live access to one named pool, not to your whole memory. The recipient must accept. You can revoke access, remove an item, or delete the save at any time; Echo blocks retrieval and delivery immediately when access ends. Echo cannot retract material a recipient already copied or opened outside Echo.
Deletion
Ask Echo to forget a save or delete your account. Deleting a save removes your capture, searchable facts and access to its evidence. Reusable public-source work may remain while another memory references it or until its cache lifecycle ends. Account deletion removes Echo’s agent conversation data before the account cascade completes. Access ends immediately; background byte cleanup may finish afterward.
After account deletion, Echo keeps only a one-way hash of the transport identity and a deletion cutoff time so delayed old messages are not recreated as new memories. The safeguard contains no message or memory content and is not available to retrieval. During alpha, Echo retains this safeguard indefinitely.
What the operator can see
Echo’s operations dashboard shows aggregate counts, costs, queue states and opaque references. It does not expose phone numbers, names, message bodies, memory contents or source URLs. Support lookup requires an exact opaque user reference.
The website and waitlist
The public website uses Google Analytics and Cloudflare security and operational logs. If you join the waitlist, Echo stores the phone number and signup time you submit in a Cloudflare D1 database separate from product memories so it can send an invitation. A waitlist entry is not automatically turned into an Echo account. During alpha, that record remains until the waitlist is manually cleared.