Privacy Policy
How EchoPilot collects, uses, stores, and protects your information.
This Privacy Policy explains how EchoPilot ("EchoPilot", "we", "our") collects, uses, stores, and protects information when you use our mobile app, our website, and any integrations you choose to connect. By using EchoPilot you agree to the practices described below.
Summary
- EchoPilot is a voice-first productivity app. It transcribes voice notes, extracts structured actions (tasks, reminders, events, notes, emails), and lets you route approved actions to services you connect.
- Before sending personal data to a third-party AI service, EchoPilot asks for permission in the app and identifies the data sent and the processor receiving it.
- EchoPilot only accesses data from connected services after you explicitly authorize the connection, and only performs actions you confirm inside the app.
- EchoPilot does not sell user data. We do not use Google user data for advertising. We do not train generalized machine-learning models on Google user data.
- You can disconnect any integration at any time. You can request account or data deletion by emailing support@echopilotapp.com.
Information we collect
- Account information - email address, display name, authentication identifiers issued by Supabase, and subscription state.
- Voice and content data - audio recordings you create on iPhone or Apple Watch, their transcripts, extracted action cards, follow-up messages, and related metadata such as session timestamps and timezone.
- Integration data - OAuth credentials and minimum sync metadata (provider identifiers, external resource IDs, sync status, last-synced timestamps) for the services you connect.
- Search index data - to power Ask EchoPilot, we convert your transcripts and action cards into numeric representations (embeddings) that capture their meaning, and store them alongside your content so you can search by meaning rather than exact keywords. Embeddings are derived from your content and are stored durably until you delete them.
- Technical data - device model, OS version, app version, anonymized usage events, and crash diagnostics used to operate and improve the service.
How we use information
- To transcribe your voice notes and convert transcripts into structured action cards.
- To store your sessions, built-in Tasks, Reminders, Notes, action cards, preferences, and integration settings so you can revisit and refine them.
- To route approved actions to the destination you select, only after you tap the explicit confirmation control inside the app.
- To build and maintain a personal semantic search index over your own transcripts and action cards, so Ask EchoPilot can answer questions about what you captured. This index is used only to answer your own queries and is never used to train third-party models.
- To provide support, security, debugging, abuse prevention, and product improvement.
Third-party AI processing
EchoPilot uses LatentKit as its third-party AI processor for speech-to-text transcription, structured action extraction, and AI follow-up refinement. LatentKit may route language-model requests to one or more model providers configured under EchoPilot's LatentKit policy, and EchoPilot may rotate between these providers to maintain reliability and quality. These providers currently include DeepSeek, Google (Gemini), OpenAI, and Anthropic.
When you allow AI processing in the app, EchoPilot may send LatentKit the following data only as needed to provide the requested feature:
- Audio recordings for speech-to-text transcription.
- Transcripts, follow-up messages, recent session thread context, selected action titles/bodies, and action metadata for extraction or refinement.
- Timezone, enabled destination names, display name, and default destination preferences so the AI can resolve dates and route actions accurately.
EchoPilot does not sell this data or use it for advertising. We require processors that receive user data to provide the same or equal protection described in this policy and to process data only to provide EchoPilot's user-facing features.
Product usage measurement
EchoPilot records how its own features are used so we can decide what to build next. This is behavioural metadata only. It never includes what you said, wrote, or asked.
- What is recorded: which feature was used and when, the platform and app version, the operating system, whether an action succeeded or failed, how long something took, and the language a meeting was detected in. Each record carries your account identifier so a person who uses two devices is counted once.
- What is never recorded: transcripts, summaries, notes, meeting content, the questions you ask or the answers you get, titles, file names, contacts, or any other free text. The fields these records may contain are a fixed list defined in code; anything else is discarded before it is stored.
- Desktop downloads and installations. When you download EchoPilot for Mac or Windows we record the request, the operating system and the version. No IP address is stored: to avoid counting one person twice we compute a one-way code from the request that changes every day and cannot be linked back to you or joined across days. When the desktop app first runs it reports an anonymous installation identifier it generated itself, so we can tell how many installations exist and how many are still in use. That identifier is not derived from your computer and is not linked to your account.
- How long it is kept: 400 days, then deleted automatically. Summary counts derived from it are kept longer and identify nobody.
- Where it goes: EchoPilot's own systems, read only by our team through an internal console. It is not shared with anyone and not used for advertising or profiling.
Deleting your account removes your personal data as described below. These usage records carry a reference to an account rather than any content, and they age out on the schedule above rather than being deleted immediately.
Google API user data
EchoPilot integrates with the following Google APIs at your option. Each scope is requested only because it is required for a specific user-facing feature, and EchoPilot accesses a Google service only after you connect it in the app.
Google Tasks (https://www.googleapis.com/auth/tasks)
- Why we need it: To create, update, complete, and delete Google Tasks that you generate from a voice note inside EchoPilot.
- What we access: Tasks on your default or selected task list. We read task IDs for tasks EchoPilot creates so we can update them later.
- How we store it: OAuth tokens encrypted at rest. Minimum sync metadata (task ID, sync status, timestamps).
Google Calendar (https://www.googleapis.com/auth/calendar.events and https://www.googleapis.com/auth/calendar.calendarlist.readonly)
- Why we need it: To create, update, and delete calendar events that you approve in EchoPilot, to let you choose which calendar EchoPilot adds events to, and to let you attach a meeting recording to the calendar event it belongs to.
- What we access for events you approve: The title, date and time, location, notes, event ID, and sync status of events EchoPilot creates for you.
- What we access to choose a calendar: The list of calendars you can edit (calendar ID, name, and which one is your primary calendar), so you can pick where new events go. The list is not stored; only the ID of the calendar you choose is saved.
- What we access for meeting recordings: To suggest the event a meeting recording belongs to, EchoPilot reads up to 8 events on your primary calendar from 2 hours before to 4 hours after the recording started: each event's title, start and end time, recurring-series ID, and attendee display names. EchoPilot does not keep or use attendee email addresses. These suggestions are shown to you and are not stored.
- What we keep when you attach an event: The event's ID, start time, recurring-series ID, and title are saved with the recording, so the meeting shows which event it belongs to and you can find it by the event title in search. Attendee names are saved only if you turn on the option to use them, and are used only to suggest who the speakers in that meeting were.
- How we store it: OAuth tokens encrypted at rest, the ID of the calendar you chose, minimum event sync metadata, and the details of any event you attached a recording to.
Google Drive (https://www.googleapis.com/auth/drive.file)
- Why we need it: To create and update documents or text files that you approve from note actions.
- What we access: Only files EchoPilot creates for you, plus their file IDs and sync status. This scope does not let EchoPilot see or open any other file in your Drive.
- How we store it: OAuth tokens encrypted at rest plus minimum file sync metadata.
How we share Google user data
- We do not sell Google user data, and we do not share it with advertisers, data brokers, or information resellers.
- We do not send data received from Google APIs to our AI processors (LatentKit and the language-model providers listed in this policy). If you choose a suggested attendee name as a speaker's name, that name becomes part of your meeting notes and is handled like the rest of your meeting content.
- Google user data is stored by our database provider (Supabase) and processed by our hosting provider (Vercel) only to run the features above.
- Otherwise we disclose Google user data only when required by law, or as part of a merger or acquisition in which it stays covered by this policy.
How we protect, keep, and delete Google user data
- OAuth tokens are encrypted at rest, and data moves between Google, EchoPilot, and your devices over HTTPS.
- Disconnecting a Google service in EchoPilot stops all access to it and deletes its stored tokens and settings. You can also revoke access at any time at myaccount.google.com/permissions.
- Sync metadata and attached event details are kept with the action or recording they belong to, and are removed when that item is permanently deleted. You can also detach an event from a recording at any time.
- Deleting your account deletes the Google user data we hold, along with the rest of your personal data, within 30 days.
Slack user data
EchoPilot requests Slack access only when you connect Slack from Integrations.
- Why we need it: To post note actions you approve to the Slack channel selected during installation.
- What we access: The selected workspace/channel metadata and permission to post messages as the EchoPilot app.
- How we store it: OAuth bot tokens encrypted at rest, plus minimum channel and sync metadata.
Other connected services and device destinations
- Todoist, Notion, and Microsoft services - if you connect them, EchoPilot stores encrypted OAuth credentials and sends only the approved action data required to create, update, send, or remove the item you confirm.
- Apple Reminders, Device Calendar, alarms, and notifications - EchoPilot requests device permissions when needed, writes approved reminders/events through device APIs, and schedules user-created reminder or task alerts on the device.
- Apple Notes, WhatsApp, and Mail - EchoPilot opens a share sheet, prefilled WhatsApp handoff, or mail composer with approved content; it does not silently save to Notes or send a WhatsApp or Mail message through these user-mediated flows.
Google API Services User Data Policy - Limited Use
EchoPilot's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements:
- Google user data is used only to provide or improve user-facing features the data was granted for.
- We do not transfer Google user data to third parties except as necessary to provide those features, comply with law, or as part of a merger or acquisition with continued policy adherence.
- We do not use Google user data to serve advertising.
- Humans do not read Google user data except with your explicit consent, for security or legal reasons, or when aggregated and anonymized.
- We do not use data obtained through Google Workspace APIs (Google Calendar, Google Tasks, and Google Drive) to develop, improve, or train generalized or non-personalized AI or machine-learning models.
How long we keep your data
- Voice notes, transcripts, and action cards are retained while your account is active. You can delete individual sessions or actions in the app.
- Search index embeddings are retained while your account is active and are deleted when you delete the underlying session or action, or when you delete the whole index under Settings > Delete Ask memory. Deleting the index does not delete your notes.
- OAuth credentials are retained only while an integration is connected. Disconnecting deletes stored tokens.
- Product usage records are kept for 400 days and then deleted automatically.
- Account deletion removes personal data within 30 days, except where retention is required by law.
Security
We use industry-standard safeguards including encrypted-at-rest OAuth credentials, HTTPS in transit, and least-privilege access controls. No internet service can guarantee absolute security.
Your choices
- Enable, disable, or disconnect integrations in the EchoPilot app at any time.
- Revoke EchoPilot's access from myaccount.google.com/permissions.
- Delete the semantic search index at any time under Settings > Delete Ask memory. Your notes, tasks, and reminders are unaffected; new captures are indexed again unless you delete it once more.
- Delete your account from inside the app under Settings > Delete account. See Account deletion for steps and retention details.
- Request data export or other privacy actions at support@echopilotapp.com.
Third-party processors
- Supabase - authentication, database, and file storage.
- LatentKit - speech-to-text transcription, structured action extraction, AI follow-up refinement, and generating the embeddings used for the Ask EchoPilot search index.
- Language-model providers (DeepSeek, Google Gemini, OpenAI, Anthropic) - language-model processing through LatentKit policy for action extraction and refinement; EchoPilot may rotate between these providers.
- PostHog - product analytics when configured.
- Paddle - payment processing and subscription management. Paddle acts as the merchant of record for EchoPilot subscriptions, which means Paddle is the seller of record and handles billing, invoicing and applicable sales tax or VAT.
- Sentry - crash and error reporting.
- Vercel - application hosting.
- Connected integration providers - Google, Todoist, Slack, Notion, Microsoft, Apple device services, and Mail only when you connect, enable, or confirm sending an action to those destinations.
Children
EchoPilot is not directed to children under 13. We do not knowingly collect personal information from children.
International users
EchoPilot may process information in the United States. By using the service you understand your information may be transferred and processed there.
Changes
We may update this policy as the product evolves. Material changes are reflected in the "Last updated" date above.
Contact
Privacy questions and data-deletion requests: support@echopilotapp.com. Account deletion steps are available at Account deletion. We respond to verified privacy requests within five business days.