Security

Your meetings are yours.

What EchoPilot stores, how it is protected, what integrations can reach, and the things we deliberately do not do with your recordings.

  • No certifications claimed
  • No ad model
0Bots joining your meetings, ever
0Actions created without your approval
30dRecoverable window after a deletion
1Identity per sign-in; accounts never merge

No selling, no ads

We do not sell user data and there is no advertising model, so there is no commercial reason for a recording to go anywhere.

Nothing sent on your behalf

No task, message, event or email leaves EchoPilot until you confirm the card in front of you.

Encrypted where it matters

HTTPS in transit, integration credentials encrypted at rest, least-privilege access to production.

Deletion you can undo

A deleted recording sits in a bin for 30 days, unreachable from search and Ask, then goes.

In depth

The details.

What we do not do

Starting here, because it is the shortest part and the part people actually want.

  • We do not sell user data.
  • We do not use your content for advertising. There is no ad model in EchoPilot, so there is no commercial reason for your recordings to go anywhere.
  • We do not create anything on your behalf without approval. No task, message, calendar event or email leaves EchoPilot until you confirm the card in front of you.
  • We do not claim certifications we do not hold. If EchoPilot obtains one, it will appear here with its scope and its date.

Your account and your data

Each account is a separate identity with its own recordings, its own entitlements and its own server-side data. Signing in with a different method creates a different account rather than merging into an existing one, and one account cannot read another's recordings.

Audio is transcribed and analysed to produce your Meeting Minutes, transcript and action cards. That processing is what the product is; it is not a separate consent to something else happening with the recording.

In transit and at rest

Traffic between the apps and EchoPilot's servers runs over HTTPS. Integration credentials are encrypted at rest, and access to production data follows least-privilege controls. No internet service can promise absolute security, and we are not going to be the first to claim it.

Integrations reach only what you connect

Every integration is opt-in. Nothing is connected by default, and connecting one authorises only that destination. EchoPilot stores encrypted OAuth credentials and sends only the data required to create, update, send or remove the specific item you confirmed.

You can disconnect an integration at any time. Doing so stops future cards routing there and leaves anything already created in that app untouched.

Deleting things

Deleting a recording moves it to a bin for 30 days with its audio and cards intact, and Restore puts it back unchanged. While it is binned it is unreachable from search, Ask, exports and every other view, so a deletion takes effect immediately from your point of view while staying recoverable from a mistake.

The Ask index can be deleted separately in Settings without deleting your recordings. That removes the search index that makes cross-meeting questions possible and leaves your audio, transcripts and minutes in place.

Deleting your whole account is documented on its own page, including what is removed and how to request it.

Recording responsibly

EchoPilot records only when you start a recording. There is no always-on listening, no bot that joins meetings on your behalf, and nothing in a participant list.

Whether you may record a given conversation is a question about your jurisdiction and the people in the room, not about the app. EchoPilot makes recording deliberate and visible on your own device; the decision to record, and telling the people you are with, remains yours.

FAQ

Questions worth answering.

How is my data handled?
Audio is transcribed and analysed to produce your minutes and action cards. We do not sell user data and do not use your content for advertising. Integrations are opt-in and their credentials are encrypted at rest. Full detail is in the Privacy Policy.
If I delete a recording, can I get it back?
Yes. Deleting a recording moves it to a bin for 30 days with its audio and cards intact, and Restore puts it back unchanged. While it is binned it is unreachable from search, Ask, exports and every other view.
Does EchoPilot create tasks automatically?
No. EchoPilot drafts a card for each commitment it finds and shows you the destination it picked. Nothing is created, updated, or sent outside EchoPilot until you tap the confirmation on that card.
iPhone, Android, Mac, Windows and web

Read the policy, then decide.

The Privacy Policy carries the full detail, including how Google API user data is handled under the Limited Use requirements.

Questions? support@echopilotapp.com