Privacy Policy

Effective date: 13 September 2026 · Last updated: 8 October 2026

Echo is a privacy-first personal briefing app for Android, with a companion app for Mac and Windows. This policy explains, in plain language, what data Echo accesses, why it needs it, where that data is processed, and the control you have over it.

The short version

You don't have to read the whole thing to trust it. Here's the essence:

1. Who we are

Echo (“Echo”, “the app”, “we”, “us”) is a personal briefing app. Echo reads information already on your phone, namely your notifications and your calendar, and turns it into a short spoken briefing, a list of who is waiting on you, a to-do list with reminders, and an assistant (“Ask Echo”) that answers questions about your day. A companion app for Mac and Windows shows the same day on your computer.

This policy applies to the Echo Android app, the Echo desktop app for Mac and Windows, and this website. It does not apply to third-party services you may separately choose to use, such as Google Gemini if you enable the optional cloud engine described below.

2. What data Echo accesses, and why

Echo is designed to read only what it needs for its features. Specifically:

Notifications

With your permission (Android's notification access), Echo reads the notifications that arrive on your phone: the app they came from, the sender, the chat or group name, the text and the time. This is the core of Echo. You choose which apps Echo hears in Apps Echo hears, and notifications from apps you switch off are not captured. Text messages reach Echo the same way, as notifications from your messaging app. Echo does not read your SMS inbox.

Calendar

If you grant calendar access, Echo reads your upcoming events (title, time and description) so your briefing and Ask Echo can tell you what's on your schedule. Echo only reads your calendar; it never creates, changes or deletes events. Android shows this as a single calendar permission covering reading and writing, but Echo only reads.

Your installed apps

Echo lists the apps on your phone so you can choose which ones it hears, and uses their names and icons to label your notifications. This list stays on your phone.

Contacts (WhatsApp replies only)

When you reply to a one-to-one WhatsApp chat and Echo can't otherwise find that chat, it may ask for contacts access. Echo then looks only at the WhatsApp entries in your contacts to find the right chat to open, keeps that one chat identifier on your phone, and reads nothing else (no names, emails or other fields). This is optional; without it Echo lets you pick the chat yourself.

Microphone (voice questions)

When you speak a question to Ask Echo on your phone, Echo uses your phone's speech recognition service to turn it into text. On most Android phones this is provided by Google and may process your audio on Google's servers, under Google's terms. The microphone is only on while you are dictating. You can always type instead.

Camera (pairing a desktop)

The camera is used only to scan the QR code shown by the Echo desktop app when you pair it. Echo reads the code and nothing else; no photos or video are saved or sent.

We collect only what serves you. Echo does not access your photos, files, location or browsing history, and it does not read your contacts beyond the WhatsApp lookup described above.

3. On-device processing

By default, Echo processes everything on your own devices. The phone uses a compact AI model (Qwen2.5 1.5B) that runs on the phone itself; the desktop app uses a larger one (Qwen2.5 7B) that runs on your computer. Echo uses them to write your briefing, answer your questions, find your to-dos, sum up busy groups and draft replies.

In this mode:

Your briefing is read aloud by your device's own text-to-speech, or by a natural voice (Piper) that you can download and that runs entirely on your device.

4. The optional cloud engine

For faster answers, Echo offers an optional cloud engine powered by Google Gemini. It is off by default and is used only if you turn it on in Settings and enter your own Gemini API key. Your key is kept on your device and is used only to call Google directly; it is never sent to us.

When, and only when, the cloud engine is on:

You can switch back to the on-device engine at any time. When the cloud engine is off, none of your content is sent to Google.

5. Echo on your desktop

If you install the Echo desktop app and pair it with your phone, the two talk to each other directly over your local network (your Wi-Fi). Nothing passes through any server of ours or over the internet. Pairing uses a one-time code that the desktop shows as a QR code.

The desktop app only listens for your phone when you turn on its engine in Settings.

6. Replies and reminders

Echo can draft a reply or suggest a quick one, but nothing is sent until you tap Send. When you do, Echo sends it through that chat's own notification reply, or opens the chat with your reply ready for you to send, so it always goes from your own account in that app. Echo does not use accessibility services and never types into other apps.

Reminders are set on your phone and shown as ordinary notifications at the time you choose. They stay on your device, apart from the copy shared with a desktop you've paired.

7. Permissions we request

Echo asks only for the permissions its features require. You can decline any of them; the related feature will simply be unavailable. You can also change them at any time in your device's settings.

Notification access

Notification listener

Lets Echo read incoming notifications for your briefing, your list and Ask Echo. This is the app's central function.

Calendar

Read calendar events

Lets Echo tell you what's on your schedule. Echo never changes your calendar. Optional.

Contacts

Find a WhatsApp chat

Asked only when replying to a WhatsApp chat Echo can’t otherwise find, and used only for that. Optional.

Microphone

Voice questions

Used only while you dictate a question to Ask Echo.

Camera

Pair your desktop

Used only to scan the pairing QR code shown by the Echo desktop app.

Notifications / Alarms

Briefings and reminders on time

Lets Echo post your briefing and reminders at the times you choose, and keep them after a restart.

Internet & local network

Network access

Used to talk to your paired desktop over your Wi-Fi, to download AI models and voices you choose, to fetch app settings, to send anonymous usage counts, and for the cloud engine if you turn it on.

8. What Echo keeps on your devices

Everything Echo keeps is stored in its private app storage on your phone (and, if you pair one, your computer):

9. Other network connections

Apart from the cloud engine and your paired desktop, Echo connects to:

The QR scanner uses Google's ML Kit, which runs on your phone and may send Google anonymous diagnostic information about how the scanner performs. No images are sent.

10. Sharing and third parties

We do not sell your personal information, and we do not share your notification, calendar or message content with anyone. We have no servers that receive it.

Your content leaves your phone only in the ways you choose: to Google Gemini if you turn on the cloud engine, to your own desktop if you pair one, to your phone's speech recognition service when you dictate a question, and to the chat app you reply in when you tap Send.

11. Advertising and analytics

Echo contains no advertising. We do not show ads and we do not integrate advertising networks or advertising trackers.

To learn which features are useful, Echo sends anonymous usage counts to a privacy-focused provider, Aptabase. These record only that a feature was used, for example that a briefing was made or played, Ask Echo was used, a to-do list was made or the engine was switched, along with basic technical details (app version, operating system and version, language, and a random session ID that changes regularly). They are not linked to your identity, need no account, and never include your content.

This is on by default and optional. Turn off Share anonymous usage data in Settings → Privacy at any time, and no usage events are sent after that.

This website does not use cookies, analytics or advertising. Our hosting provider (Vercel) may keep standard server logs, such as IP addresses, to run and protect the site.

12. Data retention and deletion

Because your content stays on your devices, you control its lifetime:

If you use the cloud engine, the text sent for a request is processed by Google to return a response, and its retention is governed by Google's terms. Echo itself keeps no copy of your content on any server, because it has none.

13. Children's privacy

Echo is intended for a general audience and is not directed to children under the age of 13 (or the minimum age required in your jurisdiction). We do not knowingly collect personal information from children. If you believe a child has used Echo in a way that raises a concern, please contact us and we will help address it.

14. Security

Keeping processing on your own devices is itself a strong safeguard: data that never leaves them can't be exposed by a server breach. Requests to the cloud engine, model and voice downloads, and usage counts all use encrypted connections. Your device's own security (screen lock and operating system protections) also protects Echo's storage.

The connection between your phone and your paired desktop stays on your local network, and once they are paired each request must carry the pairing code, but it is not encrypted. Pair them on a network you trust, such as your home Wi-Fi. No method of storage or transmission is completely secure, but we design Echo to keep what is exposed to a minimum.

15. Your rights and choices

You are in control of Echo at all times. You can:

Depending on where you live, you may have additional rights under laws such as the GDPR or CCPA (for example, to access or delete personal data). Because Echo keeps your content on your devices rather than on our servers, you can exercise these rights directly. For anything you can't do yourself, contact us using the details below.

16. Changes to this policy

We may update this Privacy Policy from time to time, for example when we add a feature or change how data is handled. When we do, we will revise the “Last updated” date at the top of this page, and for significant changes we will give a more prominent notice in the app. Your continued use of Echo after an update means you accept the revised policy.

17. Contact us

If you have any questions about this policy or about how Echo handles your data, please reach out:

Email: chandan1204@gmail.com

We aim to respond to privacy inquiries promptly.