Privacy Policy

Echoes is built on trust. This policy explains what we collect, why, who else touches it, and what stays private.

Effective July 29, 2026

Information We Collect

We collect only what we need to provide you with a safe, meaningful experience. Here is what that includes:

  • Account data: your display name, username, email address, bio, and profile picture. If you sign in with Google or with Apple, that provider confirms who you are and passes along your email address and, depending on the provider, your name and profile photo — never your password. When we receive a profile photo we save our own copy of it, so that nobody's browser has to call out to the provider just to see your profile.
  • Content you create: echoes, responses, direct messages, daily check-in answers, resonances, bookmarks, reports you send us, and everything you write inside an arc — your daily entries, the feeling you log before writing, your letter to your future self, and your retrospective notes.
  • Connection activity: when you resonate with, respond to, or message someone, we record that it happened. That history is what decides who shows up in your Sparks, whose arc presence you can see, and who can send you a gesture. Blocks and mutes are stored too.
  • A small set of product events: on our servers we note a handful of named moments, such as an arc viewed, joined or completed, a beat submitted, Sparks opened, a gesture sent, or a block or mute — each tagged with your account id and sometimes an arc id or beat number. Never the words you wrote, and never the feeling you picked.
  • Device information: browser type, operating system, IP address, general region, and your time zone. We do not track precise location.
  • On the mobile app, two more things: a push token that identifies your device to Apple's or Google's notification service, and — only if you choose to set a profile photo — permission to open your photo library for as long as it takes you to pick one image. We do not use your camera or your microphone, and we read nothing else from your device.

How We Use Your Information

Everything we collect serves a clear purpose:

  • To provide the service: displaying your profile, publishing your echoes, delivering messages, keeping your arc moving, and sending the notifications you asked for.
  • To keep the community safe: text you are about to publish is screened automatically before it goes live, and reports you send us are recorded so we can act on them.
  • To understand what is working: the small set of product events above tells us which features people actually use. It is counts and coarse ids — not reading over your shoulder.
  • To communicate with you: sending sign-in codes and links, answering support requests, and delivering notifications you have opted into.

What Stays Private, and What Others Can See

Echoes has quiet rooms and public ones. Here is exactly which is which:

  • Public: your echoes and responses, and your profile — display name, username, bio, and photo. Profile photos are served from a public address, so anyone holding the link can load the image.
  • Private by default: everything you write inside an arc. Your daily entries, the feeling you log before writing, and your retrospective notes are yours alone. None of it reaches another person unless you take one of the two opt-ins below.
  • Sealed: your letter to your future self. You write it once, and our server refuses to hand it back — even to you — until you finish the arc.
  • Two separate opt-ins, offered per entry. You can publish an entry onward as an echo, which makes its first 280 characters public under your name. Or you can share it with your cohort, which shows up to a 200-character excerpt — with no name and no timestamp — to other people walking the same arc on the same day, and only once at least five people have shared on that step. Neither one implies the other, and the rest of the entry is never shared.
  • Warmth given to an anonymous excerpt stays anonymous. We store who gave it only to stop the same person giving it twice; it is never shown to the author, never attached to your name, and the author only ever sees a count.
  • Between the two of you: direct messages. Someone has to accept your request before a thread opens, and either of you can block or mute the other at any time.

How We Store and Protect Your Data

Your data is stored in an encrypted database managed by a trusted infrastructure provider. All information is encrypted in transit and at rest. Access is restricted to authorized systems, and we follow the principle of least privilege — no one sees more than they need to. We review our security practices regularly and strengthen them as the platform grows.

Information Sharing

A handful of companies process data on our behalf so that Echoes can run. Each one is listed here with what it actually receives:

  • Database, sign-in, and file storage (Supabase): holds your account, your content, and the images you upload, and sends your sign-in emails and codes.
  • Hosting (Vercel): runs the website and its server code, and so handles every request you make to Echoes.
  • Automated safety screening (OpenAI): text you are about to publish is sent to OpenAI's moderation service just before it goes live — an echo, an arc entry you chose to publish, or the excerpt you chose to share with your cohort. Only the part that would become visible to others is sent, never the rest of a private entry. Direct messages and responses are not sent to it at all.
  • Error monitoring (Sentry): when something breaks, Sentry receives the technical details — what failed, where in the code, the browser or server involved, and when. It does not receive the content of your echoes, responses, or messages. It also receives timing measurements from a sample of requests, and it records a replay of a small sample of browsing sessions in which all text and anything you type is masked before it ever leaves your device.
  • Product analytics (PostHog): receives the small set of named product events described above, tagged with your account id. It receives nothing you wrote.
  • Push notifications (Expo, Apple, Google): if you turn on push notifications in the mobile app, each notification is handed to Expo's push service and on to Apple or Google to reach your device. What we send them is deliberately content-free: who it is from and what kind of notification it is — never the text of a message, a response, or anything you have written. The words themselves only appear once you open the app. Turning off the matching push notification in your settings stops the notification entirely.

We may also disclose information where the law requires it, or where we believe in good faith that it is necessary to prevent serious harm to someone.

We do not sell, rent, or trade your personal information. We do not share your data with advertisers. Echoes has no ads and no intention of introducing them.

Your Rights and Choices

You are in control of your information. Here is what you can do at any time:

  • See your information: your echoes, responses, messages, arc entries, and profile are all visible to you inside the app. We do not have a one-click export yet — if you want a copy of your data, ask us through our contact page and we will put it together for you.
  • Delete your account: you can do this yourself, from your profile settings. The next section explains exactly what happens.
  • Update your profile: change your display name, username, bio, or avatar from your profile settings whenever you like.
  • Manage notifications: choose which emails and which push notifications you receive from your profile settings. Signing out of the mobile app removes that device's push token.
  • Choose who can reach you: block or mute anyone. Blocking stops messages and gestures in both directions and takes you out of each other's shared rooms.

When You Delete Your Account

Deleting your account is something you do yourself, from your profile settings, and it takes effect immediately. Your display name, username, bio, and profile photo are erased, your notification settings are switched off, and you are signed out for good — you will not be able to sign back in.

Your name comes off your content, but the content itself stays. Echoes you published, responses you left, and messages you sent remain in the threads and conversations other people are part of, shown as coming from a deleted account — no name, no username, no photo. Your private arc entries stop being shown to anyone, and the anonymous cohort pool drops deleted accounts entirely.

We would rather be plain about this than sound tidier than we are: deleting your account scrubs your identity and closes the door, but it is not a wipe of every row from our database. If there are particular things you want gone before you leave, delete them yourself first — or ask us through our contact page and we will take care of it.

Cookies and Local Storage

On the web, Echoes uses cookies and local storage sparingly: your sign-in session, your language, and your theme. There is one more — our error-monitoring tool keeps a short-lived session id in your browser so it can tie one session's technical events together. We use no advertising cookies and no third-party tracking cookies, and our product analytics runs on our servers rather than in your browser. On the mobile app, your session and your device's push token are kept in the operating system's secure storage.

Children's Privacy

Echoes is not intended for anyone under the age of 13. We do not knowingly collect personal information from children. If we learn that a child under 13 has created an account, we will delete the account and all associated data promptly.

Changes to This Policy

If we make meaningful changes to this policy, we will update the effective date at the top of the page and notify you through the app. We encourage you to review this page from time to time. Continued use of Echoes after a change means you accept the updated policy.

Contact Us

If you have questions about this policy or want to exercise any of your rights, we are here to help. Reach out through our contact page.