Privacy Policy
In short: Echo is a private journal. We do not sell your journal entries or photos. We store your data so you can write, call, print, and use connected AI tools. When you use voice polish, phone transcription, or ChatGPT/Claude connectors, those providers process only what is needed for the feature you use.
1. Who we are
Echo is a voice journal application operated as a private, invite-only beta (not an open public social network). Access is limited to operator-approved Google accounts. For questions about this policy or your data, contact the instance operator at john@extendica.com.
2. What we collect
Depending on how you use Echo, we may process:
- Account & identity — Google account email and subject ID if you sign in with Google (scopes: openid, email, profile); and/or an invite-only email + password account (any email domain). Passwords are stored only as one-way hashes. We may email verification and password-reset links via our email provider (Resend). A shared operator break-glass password may exist for the instance owner. Sign-in is limited to allowlisted / invited emails.
- Journal content — titles, body text, dates, goals, writing style card / voice pack samples you save.
- Photos — images you attach to entries or claim via the photo claim flow (bytes stored in a private cloud bucket; metadata in our database).
- Phone — allowlisted caller numbers, call signaling, and audio processed for transcription / optional spoken “Echo” segments.
- Usage & operations — feature usage and approximate cost metrics for admins (including per-user cost estimates for beta control); technical logs (errors, entry IDs/titles) for reliability — not full journal bodies as a product of logging. Invited emails and invite status for access control; waitlist emails/names/notes you submit from the public landing page (so we can offer a beta invite later).
- Print orders — book title, date range, dedication, shipping address you enter for a print job, and job status (sandbox print API today).
- Connected AI tools (MCP) — when you connect ChatGPT or Claude and invoke Echo tools, those hosts send and receive tool data (for example search results or entry snippets) under that host’s product and your consent.
We do not run advertising trackers or third-party analytics pixels on the journal or login pages.
3. Why we process it
- Provide your private journal (web, phone, CLI, and MCP tools)
- Authenticate you and enforce allowlists / roles
- Polish or generate entry drafts in your voice when you ask
- Transcribe phone dumps and optional spoken responses
- Store and show photos you attach
- Build printable PDFs and (when you choose) submit print jobs
- Keep the service secure and operable (rate limits, admin usage view)
4. Where data lives
| Data | Where |
|---|---|
| Journal text, profiles, OAuth/token metadata, media metadata |
SQLite on a Fly.io volume in Dallas (dfw), path
/data
|
| Photo bytes |
Private Google Cloud Storage bucket
echo-journal-media-prod, region
US-SOUTH1 (Texas). Not public.
|
| API keys & portal password secret | Fly.io secrets / operator environment — never in the public repo |
5. Who processes data on our behalf
To run Echo we use subprocessors. Content leaves our servers only when a feature requires it:
- xAI (Grok) — voice, speech-to-text path, and writing polish / generation you request.
- Twilio — phone calls to the journal line (signaling and media).
- Google — OAuth sign-in identity; Cloud Storage for private photos.
- Fly.io — application hosting and encrypted-at-rest volume for the database.
- Lulu — print-on-demand when you submit a job (sandbox today); may fetch short-lived signed PDFs.
- OpenAI (ChatGPT) / Anthropic (Claude) — only if you connect Echo as an MCP connector and use tools in that product. Those hosts process the tool inputs and outputs you trigger. Review their privacy policies as well.
We do not sell your personal journal data, and we do not run a pipeline that exports full journals to the operator’s personal email.
6. Passwords, sessions, and security
- Per-user account passwords are stored only as one-way scrypt hashes in our database — never as plain text. An optional operator break-glass password lives as a server secret (or scrypt hash in environment config), not in journal rows.
- Email verification and password-reset links are one-time tokens (stored hashed) and may be delivered by Resend when configured.
-
Web sessions use an httpOnly cookie signed with a server secret
(
echo_session). - CLI and MCP tokens are stored as cryptographic hashes, not reversible passwords.
- Photos use private storage and short-lived signed URLs for upload/view.
- Phone access is limited by caller allowlist; web login by email allowlist (Google and/or invited email+password accounts).
No system is perfect. Please use a strong unique password, verify your email, and only connect MCP hosts you trust.
7. Retention & deletion
Journal entries and photos are kept until you delete them or the operator removes data for this instance. Session cookies expire (default on the order of weeks). Print file links expire. There is not yet a fully automated multi-year purge schedule for all content.
You can delete individual entries in the web app or via connected tools. For a full account wipe or a copy of your data, email the contact above.
8. Your choices & rights
Depending on where you live (for example under GDPR or CCPA/CPRA), you may have rights to access, correct, delete, or obtain a portable copy of personal data, and to object to certain processing. This private instance will honor reasonable requests from allowlisted users — contact the operator.
California residents: we do not “sell” or “share” personal information for cross-context behavioral advertising as those terms are commonly defined. We do not use your journal content for advertising.
9. Children
Echo is not directed at children under 13 (or the equivalent minimum age in your region). We do not knowingly collect data from children.
10. International users
Primary storage is in the United States (Dallas / Texas regions for app and photos). If you access Echo from elsewhere, you understand that processing may occur in the U.S. and in the regions of the subprocessors listed above.
11. Changes
We may update this policy as the product or infrastructure changes. The “Last updated” date at the top will change. Material changes for allowlisted users will be communicated in a reasonable way (for example in-app or by email).
12. Contact
Privacy questions or data requests:
john@extendica.com