Privacy Policy
MyEcho is a digital legacy vault. We take your privacy seriously. This policy explains what data we collect, why we collect it, how we protect it and how long we keep it.
1. Information We Collect
We collect only what is necessary to provide the service:
- Account information: your name, email address and, if you provide them, phone number and date of birth.
- Vault contents: the messages and entries in your vault, encrypted on your device before upload.
- Uploaded files: photos, videos, audio and documents you upload, stored in private cloud storage.
- Scheduled deliveries: the messages and files you schedule for recipients, and the recipients' names and email addresses.
- Beneficiary and trusted-contact information: names and contact details of the people you designate.
- Check-in activity: timestamps of your check-ins.
- Security information: sign-in times, device and browser type, approximate location derived from your IP address, trusted devices, and security events such as password or PIN changes.
- Billing information: your plan, storage size, add-ons, payment status and invoices. Payments are processed by Stripe; we never receive your full card number.
- Backups: on paid plans, daily backup copies of your encrypted vault, your scheduled deliveries and your uploaded files.
- Connected accounts: if you import Google Contacts, the names and emails you import are stored in your encrypted vault.
2. How We Use Your Information
- To operate your vault, store and back up your files, and keep your account secure.
- To send check-in reminders, security alerts and account, billing and backup notifications.
- To deliver your messages to your recipients when the conditions you set are met.
- To process payments, manage your plan and prevent fraud and abuse.
- We do not sell your data. We do not use your vault contents for advertising.
3. Encryption and Access
Your vault is encrypted on your device with AES-256-GCM. The key is derived from your Vault PIN — which never leaves your device — together with a server secret that is only released after your PIN is verified. We cannot read your vault.
Uploaded files and scheduled deliveries are handled differently, because we have to store and deliver them for you: files are kept in a private storage bucket that only your signed-in session (or your recipients' secure delivery links) can reach, and scheduled messages are encrypted with a MyEcho delivery key. All connections use HTTPS. Staff access to accounts is limited to what's needed to support you and every admin action is recorded in an audit log. See Security for technical details.
4. Data Retention
- Your vault, files and account: kept for as long as your account exists. Cancelling a plan or letting a trial end does not delete them.
- Deleted accounts: when you delete your account, it can be restored for 30 days. After that, your vault, files, scheduled deliveries, backups and account details are permanently erased.
- Backups: daily backups are included with paid plans. Deleted files and older snapshots stay recoverable for 30 days, after which their backup copies are permanently removed. If a paid plan ends, the remaining backups are removed once their 30 days have passed.
- Sessions: end after 30 days without use, and after 180 days at most. Trusted devices are forgotten after 180 days without use. You can end both at any time.
- Security log: sign-in and security events are kept for 365 days.
- Billing records: payment and invoice records are kept as long as required for tax, accounting and legal purposes, without your vault contents — including after your account is erased.
- Admin audit log: records of support and admin actions on accounts are kept for security and legal compliance.
5. Third-Party Services
- Cloudflare: hosting, database, CDN and DDoS protection. Your data passes through Cloudflare's network.
- Backblaze B2: private storage for uploaded files and for the daily backups included with paid plans.
- Stripe: payment processing. Subject to Stripe's Privacy Policy.
- Resend: sends our emails, including verification codes, alerts and deliveries.
- Google: used only when you choose Google sign-in or import Google Contacts, with read-only access limited to what you approve.
6. Your Rights
You have the right to:
- Access and export your vault at any time from Settings.
- Correct your account details, and delete your account from Settings (with a 30-day restore window).
- See your recent sign-ins and security events, and sign out other devices, from Settings → Security.
- Revoke connected account permissions (e.g., Google) at any time.
- Ask us about the data we hold about you by emailing myechosupport@gmail.com.
7. Cookies and Local Storage
We use only functional cookies: a secure session cookie that keeps you signed in, and a trusted-device cookie that lets a device you've verified skip the two-step code. Both are HttpOnly and cannot be read by page scripts. The app also stores small preferences on your device, such as your theme and your name for the sign-in screen. We do not use advertising or tracking cookies.
8. Children's Privacy
MyEcho is for adults and is not directed at children under 13. We do not knowingly collect personal information from children.
9. Changes to This Policy
We may update this policy. We will notify you by email if we make material changes. Continued use of the service after changes constitutes acceptance.
10. Contact
Questions about this policy? Email us at myechosupport@gmail.com.