Security
Your vault is encrypted on your device before it is uploaded. We store an encrypted blob, and the key is derived from your Vault PIN — which never leaves your device — combined with a server secret that is only released after your PIN is verified, with lockouts after repeated wrong guesses. Messages you schedule for delivery are additionally sealed with a MyEcho delivery key so they can be released to your recipients.
Encryption details
| Layer | Implementation |
|---|---|
| Vault encryption | AES-256-GCM with a random 96-bit IV for every save, performed on your device |
| Vault key | PBKDF2-SHA256 (310,000 iterations) over your Vault PIN on your device, combined through HKDF with a per-account server secret that is released only after the PIN check succeeds. Wrong guesses trigger escalating lockouts (30 seconds up to 4 hours). |
| Scheduled deliveries | Messages and files you schedule for recipients are sealed with a MyEcho delivery key (AES-GCM) so they can be released when a delivery is confirmed |
| Media files | Stored in a private Backblaze B2 bucket and served only through authenticated MyEcho requests. Media is protected by access control and TLS, not by your Vault PIN. |
| Daily backup (included with paid plans) | Daily copies of your vault and media in a separate, private backup area. Deleted files and older snapshots stay recoverable for 30 days; after that, expired copies are permanently deleted, including every stored version. Storage credentials never leave our servers. |
| Sessions | Random opaque token in an HttpOnly, Secure, SameSite=Strict cookie. Only a hash is stored; sessions expire after 30 days of inactivity (180 days at most) and can be revoked from Settings. |
| Passwords at rest | PBKDF2-SHA256 with a unique random salt per account; plaintext passwords are never stored or logged |
| Two-step verification | Authenticator-app codes (TOTP) with replay protection, plus ten single-use recovery codes stored as keyed hashes |
| Transport security | HTTPS only via Cloudflare, with HSTS and a strict Content Security Policy |
What we can and cannot see
We cannot read your vault: it is encrypted on your device and the key depends on a PIN we never receive. We can technically access media files you upload and messages you schedule for delivery, because we have to deliver them for you — they are used only to store, back up and deliver them as you ask, and every admin action on an account is recorded in an audit log. We also see account metadata (email, plan, timestamps), delivery logs (recipient email, sent time) and anonymous usage metrics.
Delivery security
Scheduled deliveries are triggered by our check-in system, not by a single point of failure. Legacy and Family tier deliveries require confirmation from a trusted contact before any content is sent. Deliveries are paused while an account is scheduled for deletion. Delivery logs are retained for your review in the app.
Responsible disclosure
If you discover a security vulnerability in MyEcho, please report it to us before disclosing publicly. Our contact details are also published at https://myechoapp.org/.well-known/security.txt. We commit to acknowledging your report within 48 hours and providing a fix timeline within 7 days for critical issues.
Contact: myechosupport@gmail.com — include "Security Disclosure" in the subject line.
Data retention and deletion
When you delete your account, you are signed out everywhere, billing stops renewing and deliveries are paused. For 30 days you can restore the account from the link we email you. After that window, your vault, media, backups and account record are permanently erased. Payment records we are legally required to keep are retained without your vault content. You can export a full encrypted backup from Settings before deleting. See our Privacy Policy for full retention details.
Third-party services
- Cloudflare — hosting, DDoS protection, database and key-value storage. Cloudflare processes traffic metadata but cannot read your encrypted vault.
- Backblaze B2 — private object storage for media files and the daily backups included with paid plans.
- Stripe — payment processing. MyEcho never sees or stores full card details; billing runs through Stripe's PCI-DSS certified infrastructure.
- Resend — transactional email (verification codes, security alerts, deliveries).
- Google — optional sign-in and Contacts import. Only used if you start it; scopes are limited to what you authorize.