Legal
Privacy Policy
Last updated: April 24, 2026
Echo is committed to protecting your privacy. This policy explains what data we collect, why we collect it, and how we handle it across our autonomous AI operations platform.
1. Information We Collect
We collect information you provide directly, information collected automatically when you use our platform, and information from third-party sources.
Information you provide includes: account registration data (name, email, password), organisation and brand profile information, content you submit such as prompts and campaign materials, payment and billing information processed via our payment provider, and communications you send us.
Information collected automatically includes: usage data (pages visited, features used, operator runs triggered), device and browser information, log data and crash reports, and cookies and similar tracking technologies.
When you connect external platforms (e.g. YouTube, creator networks, social APIs), we collect data returned by those platforms in accordance with their terms and your authorisation.
2. How We Use Your Information
We use the information we collect to provide, operate, and improve the Echo platform and its AI operators; to process and fulfil your account and subscription; and to personalise your experience.
We may also use your information to train and refine our AI models using aggregated, de-identified data only (unless you explicitly consent otherwise); to send transactional communications such as operator run results and payment confirmations; and to send product updates where you have opted in.
We also use your data to detect and prevent fraud, abuse, or security incidents, and to comply with our legal obligations.
3. AI Processing & Your Data
Echo is an autonomous AI platform. Prompts, context, and outputs generated through our operators are processed by large language models (LLMs) hosted by our AI infrastructure partners. These interactions are logged for performance monitoring, debugging, and safety evaluation.
We do not use your individual prompts or outputs to train foundational models operated by third parties without your explicit consent. We may use aggregated, de-identified usage patterns to improve our own orchestration layers and operator playbooks.
Certain operator runs require passing contextual data to LLM providers (including Anthropic and Google via the Vercel AI Gateway). These providers process data under their own privacy policies.
Our platform maintains conversation memory and agent context to improve operator continuity. This data is stored securely and is scoped to your organisation.
5. Data Retention
We retain your personal information for as long as your account is active or as needed to provide our services.
Account data is retained for the duration of your subscription and up to 90 days after deletion. Agent run logs and operator outputs are retained for up to 24 months. Billing records are retained for 7 years as required by applicable regulations. Analytics and usage data may be retained in aggregated, de-identified form indefinitely for product improvement.
You may request deletion of your data at any time (see Section 8).
6. Data Security
We implement technical and organisational measures to protect your information, including encryption at rest and in transit (TLS 1.2+), role-based access controls with organisation-scoped data isolation, regular security audits, and secure credential handling.
No security system is impenetrable. We encourage you to use strong passwords and enable two-factor authentication on your account.
8. Your Rights & Choices
Depending on your location, you may have rights to: access a copy of your personal information; request correction of inaccurate data; request deletion of your personal data; request your data in a portable format; object to certain processing activities; restrict how we use your data; and withdraw consent where processing is consent-based.
To exercise any of these rights, contact us at privacy@humanreason.ai. We will respond within 30 days. EEA and UK users also have the right to lodge a complaint with their local supervisory authority.
9. International Data Transfers
Echo operates globally. Your information may be transferred to and processed in countries other than your own, including the United States, where our primary infrastructure is hosted.
We ensure appropriate safeguards are in place for cross-border transfers, including Standard Contractual Clauses where applicable.
10. Children's Privacy
Echo is designed for professional brand marketing teams and is not intended for individuals under the age of 16. We do not knowingly collect personal information from children. If you believe we have inadvertently collected such information, please contact us and we will promptly delete it.
11. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the date at the top of this page and, where appropriate, send an in-app notification or email. Your continued use of the platform after changes take effect constitutes your acceptance of the updated policy.
12. Contact Us
If you have questions or requests regarding this Privacy Policy, please contact us at privacy@humanreason.ai. For users in the European Economic Area, you may also contact our designated EU representative or lodge a complaint with your local data protection authority.
Questions about your data? Contact our privacy team
Also see our Terms of Service