MyEcho

Security

How we protect your vault, your files, and your legacy.
Encrypted on your device

Your vault is encrypted on your device before it is uploaded. We store an encrypted blob, and the key is derived from your Vault PIN — which never leaves your device — combined with a server secret that is only released after your PIN is verified, with lockouts after repeated wrong guesses. Messages you schedule for delivery are additionally sealed with a MyEcho delivery key so they can be released to your recipients.

🔐
Vault encrypted on your device
Your vault is encrypted in the app with AES-256-GCM before upload. The key is derived on your device from your Vault PIN, which is never sent to MyEcho.
📱
New-device verification
With two-step verification on, every new device must enter a code. Trusted devices are listed in Settings → Security and can be revoked at any time.
🔑
Private media
Photos, videos and documents live in a private storage bucket with no public links. Every download is checked against your signed-in session first.
🧾
Activity you can see
Sign-ins, new devices, password and PIN changes, plan changes and backups are recorded in your security log, and we email you about the important ones.

Encryption details

LayerImplementation
Vault encryption AES-256-GCM with a random 96-bit IV for every save, performed on your device
Vault key PBKDF2-SHA256 (310,000 iterations) over your Vault PIN on your device, combined through HKDF with a per-account server secret that is released only after the PIN check succeeds. Wrong guesses trigger escalating lockouts (30 seconds up to 4 hours).
Scheduled deliveries Messages and files you schedule for recipients are sealed with a MyEcho delivery key (AES-GCM) so they can be released when a delivery is confirmed
Media files Stored in a private Backblaze B2 bucket and served only through authenticated MyEcho requests. Media is protected by access control and TLS, not by your Vault PIN.
Daily backup (included with paid plans) Daily copies of your vault and media in a separate, private backup area. Deleted files and older snapshots stay recoverable for 30 days; after that, expired copies are permanently deleted, including every stored version. Storage credentials never leave our servers.
Sessions Random opaque token in an HttpOnly, Secure, SameSite=Strict cookie. Only a hash is stored; sessions expire after 30 days of inactivity (180 days at most) and can be revoked from Settings.
Passwords at rest PBKDF2-SHA256 with a unique random salt per account; plaintext passwords are never stored or logged
Two-step verification Authenticator-app codes (TOTP) with replay protection, plus ten single-use recovery codes stored as keyed hashes
Transport security HTTPS only via Cloudflare, with HSTS and a strict Content Security Policy

What we can and cannot see

We cannot read your vault: it is encrypted on your device and the key depends on a PIN we never receive. We can technically access media files you upload and messages you schedule for delivery, because we have to deliver them for you — they are used only to store, back up and deliver them as you ask, and every admin action on an account is recorded in an audit log. We also see account metadata (email, plan, timestamps), delivery logs (recipient email, sent time) and anonymous usage metrics.

Delivery security

Scheduled deliveries are triggered by our check-in system, not by a single point of failure. Legacy and Family tier deliveries require confirmation from a trusted contact before any content is sent. Deliveries are paused while an account is scheduled for deletion. Delivery logs are retained for your review in the app.

Responsible disclosure

If you discover a security vulnerability in MyEcho, please report it to us before disclosing publicly. Our contact details are also published at https://myechoapp.org/.well-known/security.txt. We commit to acknowledging your report within 48 hours and providing a fix timeline within 7 days for critical issues.

Contact: myechosupport@gmail.com — include "Security Disclosure" in the subject line.

Data retention and deletion

When you delete your account, you are signed out everywhere, billing stops renewing and deliveries are paused. For 30 days you can restore the account from the link we email you. After that window, your vault, media, backups and account record are permanently erased. Payment records we are legally required to keep are retained without your vault content. You can export a full encrypted backup from Settings before deleting. See our Privacy Policy for full retention details.

Third-party services