IDITOR, INC. · d/b/a ECHO
Privacy Policy
Iditor, Inc., d/b/a Echo (“Echo,” “we,” “us,” or “our”), provides a user-directed memory hosting, synchronization, retrieval, and sharing service for adults. Echo helps you store, organize, extract, retrieve, and use “memories” across supported tools and interfaces, including the Echo MCP tools, the EchoMem web platform, the Echo Chrome Extension, and Echo Chat (collectively, the “Service”).
This Privacy Policy describes how we collect, use, share, and protect personal information in connection with the Service, our website, and related support activities. By using the Service, you acknowledge the practices described here.
Echo is intended only for adults 18 and older. See the Children’s Privacy section below.
Your control. You own your content. Echo stores and processes your memories at your direction. Memories are private by default and are shared only when you choose to share them. Echo does not use your raw conversations or extracted memories to train general-purpose AI models by default (see “How We Use Information” and “Third-Party AI Processing”).
Information We Collect
We collect information you provide directly, the memory content you direct Echo to store, and information collected automatically.
1.1 Information you provide. Account and contact data (name, email, username, password); your representation that you are at least 18; and the content of your support requests and other messages to us.
Payment data. If you purchase a paid plan on our website, payment is processed by Stripe. Your payment card details are collected and processed directly by Stripe under its own terms and privacy policy; Echo does not receive or store your full card number. We receive limited billing and transaction information (such as confirmation of payment, amount, and a card reference) to manage your subscription.
1.2 Memory content. The Service stores the content you direct it to remember, including:
- Source content — raw conversations, uploaded files, notes, prompts, and outputs you or the Service capture. Echo stores raw source conversations as a standard part of the Service, to enable re-extraction, provenance, source references, and regenerating memories for your account.
- Extracted memories — the memories and summaries Echo generates from source content.
- Embeddings and indexes — vector representations and search indexes derived from your content to enable retrieval.
- Visibility and relationship data — whether a memory is private, friend-gated, or public, and friend relationships you establish.
- Associated metadata — timestamps, source linkage, the surface a memory came from, and similar contextual information.
You retain ownership of your memory content. We process it to provide the Service, as described in this Policy.
1.3 Information collected automatically. We and our service providers may collect technical and usage information, such as device and connection data (including IP address or a privacy-safe hash) and usage and event data (such as audit events for memory creation, update, deletion, export, sharing, and connector authorization). Raw conversations, secrets, private memories, and similar sensitive content are not written to standard logs, analytics, or error trackers; those receive redacted previews, hashes, identifiers, event type, surface, and status only.
1.4 Surface-specific collection.
- Chrome Extension. When you connect a supported AI chat provider — ChatGPT (OpenAI), Claude (Anthropic), Gemini (Google), DeepSeek, Grok (xAI), or Perplexity — the Extension uses your existing logged-in session with that provider to access your conversations on your behalf, including reading your conversation list (which may include your full conversation history with that provider) so you can select which conversations to extract. You connect each provider individually; you see an indicator when the Extension is active; access in incognito is off by default. The providers are independent of Echo, which is not affiliated with or endorsed by them; your use of each provider is governed by that provider’s own terms, for which you are responsible. Extension data is not used for advertising, data brokerage, creditworthiness or lending decisions, or unrelated profiling (Chrome Limited Use).
- MCP Server / npm Package. The Echo MCP server is a user-installed npm package that lets you and agents you authorize save conversations, create, retrieve, and search memories, manage visibility, and send or respond to friend requests. Memory writes default to private. On-demand tools can read the coding-session logs your local tools (for example, Codex or Claude Code) write to named directories on your machine so you can turn them into memories or compute a context-health score when you invoke them; core memory tools do not broadly scan your filesystem. Setup may modify local configuration or instruction files for the coding agents you choose to configure. The MCP server runs as a persistent local process while in use and performs standard npm registry version checks (which do not send your personal data). Product-analytics events from the MCP tools are sent to our analytics provider as described in the Cookies, Analytics, and Diagnostics section. A broader local “Agent Doctor” scan runs only after its own separate consent and is distinct from the on-demand tools above. The MCP server does not sign in to, or retrieve conversations from, any third-party provider account on your behalf.
- Echo Context HUD (local companion). The optional Context HUD is distributed with the MCP npm package and adds a local context-health display. Unlike the on-demand MCP tools, while it is running the Context HUD reads supported local Codex and Claude coding-session files continuously, including in the background while its window is hidden, and on macOS may observe which application is in the foreground to select the session you are viewing; this observation is used locally and is not itself uploaded. These files can contain source code, credentials, or secrets. Context-health scoring is performed on your device and does not by itself upload your session contents.
- What the Context HUD sends to Echo. While its interface is open, the Context HUD makes authenticated requests to Echo (using your stored access token) for account/plan status and to check whether the active session already has a saved checkpoint; these do not send your transcript. If you choose to start a new session with context (renewal) or create a checkpoint, it sends the active session’s user and assistant text, with client/source, session type, conversation key, and title, to Echo for AI-assisted memory extraction and storage under your account. Tool calls, tool results, and thinking blocks are kept local and are not included. This renewal is designed to occur through a user action.
- Context HUD local storage and controls. The Context HUD stores window and display preferences, recent-session metadata (including session identifiers, titles, project labels, and source-file paths), generated carryover/checkpoint text, checkpoint-status records, and the access token used for cloud calls; carryover and checkpoint caches are kept for a limited period, and other local files may persist until you remove them. You can skip the HUD, quit it, avoid transcript upload by not invoking renewal, disable launch at login, and omit optional coding-agent hooks. Hiding the HUD or the “only show when Codex/Claude is open” option affects visibility, not local scanning. Deleting your Echo account or logging out does not by itself remove these local files; remove them by quitting the HUD, disabling launch at login, and removing the local Echo files.
- Echo Chat. Uses your memories to personalize responses and may create or update memories from your conversations with it.
- EchoMem web platform. Stores your source conversations, extracted memories, visibility settings, relationships, audit events, and account controls, and provides a privacy dashboard to manage them.
1.5 Information about others. Your memory content may include information about other people. You are responsible for having the rights and lawful bases needed to provide that content, as described in our Terms.
Prohibited and Sensitive Data
You may not use Echo to store or process personal information from or about anyone under 18. This is a strict condition of use. Unless expressly supported under a separate written agreement, you also may not store or process protected health information, payment card data, passwords or secrets, government identifiers, biometric data, or precise geolocation. Echo may block, quarantine, redact, or decline to process content it identifies as restricted.
How We Use Information
We use information to:
- Provide and operate the Service — hosting, storing, extracting, indexing, retrieving, and synchronizing memories at your direction, and enabling sharing you initiate.
- Personalize your experience — recalling your memories and preferences, and in Echo Chat using memories to personalize responses.
- Maintain, secure, and support — authentication, abuse prevention, incident response, troubleshooting, and responding to requests.
- Improve the Service — using aggregated, de-identified, or operational data, consistent with applicable law.
- Communicate with you — service announcements, security alerts, and administrative messages.
- Comply with law and protect rights.
3.1 No training of general-purpose models by default. Unless you separately and affirmatively agree, Echo does not use your raw conversations or extracted memories to train, fine-tune, or benchmark general-purpose AI models. A no-training default applies across your account, sources, and memories. We may use aggregated, de-identified, or operational data to maintain, secure, analyze, and improve the Service.
3.2 No sale; no memory-based targeted advertising. Echo does not sell your memory data and does not use your memory data for targeted advertising. We do not use tracking pixels or advertising cookies, and we do not share personal information for cross-context behavioral advertising.
Third-Party AI Processing
To create, extract, and organize memories, content you direct Echo to process is transmitted to third-party AI providers and processed by them in readable form. This is a core part of how the Service works. We use OpenAI for embedding generation and Google (Gemini / Vertex AI) for memory extraction and related structured generation. These providers process your content under their own terms and privacy policies.
Because content is processed in readable form by these providers, the Service is not end-to-end encrypted. We describe our encryption practices in the Security section below.
OpenAI (embeddings). OpenAI processes text you submit to return embeddings. OpenAI states that data submitted to its embeddings API is not used to train its models and has no application-state retention, and may be retained for abuse monitoring for up to 30 days unless different approved controls apply or longer retention is legally required.
Google Gemini / Vertex AI (memory extraction). Google processes prompts, context, and generated outputs to extract and structure memories. We use paid Gemini / Vertex AI services. Google states that, for paid services, it does not use prompts or responses to train its models, but may retain prompts, context, and outputs for up to 55 days for abuse monitoring, policy enforcement, and required legal disclosures, and that flagged content may be reviewed by authorized Google personnel. We do not route your content through unpaid Gemini quota or free AI Studio services.
No training on your content. Based on the terms of the services and tiers we use, neither OpenAI (embeddings) nor Google (paid Gemini / Vertex AI) uses your content to train their general-purpose models, and Echo does not use your content to train models by default (see Section 3.1).
Sharing and Disclosure
We share personal information only as described below.
- At your direction (sharing memories). Memories are private by default. If you make a memory public or friend-gated, it may be viewed, copied, or used by others per the setting you select. Reversing sharing is subject to technical and legal limits.
- Service providers and subprocessors — vendors that help us operate the Service, including hosting and infrastructure providers, our analytics provider (Amplitude, for first-party product analytics across the Chrome Extension, MCP tools, web platform, and Echo Chat, and for consent-gated research-page analytics), our crash-diagnostics provider (Google Firebase Crashlytics, for Echo Chat), and our payment processor (Stripe, for paid plans), each acting as a processor/service provider under a data-processing agreement and under obligations to protect the information. See our Subprocessor List.
- Third-party AI providers — as described in Section 4.
- Legal and safety — to comply with law, respond to lawful requests, enforce our Terms, or protect rights, safety, and property.
- Business transfers — in connection with a merger, acquisition, financing, or sale of assets, or in insolvency or similar proceedings.
Data Retention
We retain personal information for as long as needed to provide the Service and for the purposes in this Policy, subject to the controls in Section 7. Different categories of data are retained on different schedules:
- Active production systems — when you delete your account or make a verified deletion request, we act on it promptly and remove your User Content, memory data, embeddings, and associated account records from our active production systems without undue delay, except where limited retention is required for legal, security, fraud-prevention, dispute-resolution, or compliance reasons. We respond to and act on deletion requests within the timeframe required by applicable law.
- Database backups — deleted data may persist in encrypted database backups until those backups expire. Our database provider (Supabase) retains daily backups for 7 days on our current plan.
- Server logs — our hosting provider (Vercel) retains runtime logs for approximately 1 day on our current plan. We design our systems so that raw User Content and memory data are not written to logs, build logs, or deployment artifacts.
- Public-memory matching indexes — if you revoke public status or delete public memory, cached or indexed copies used for matching may take up to 30 days to be fully removed.
- AI-provider abuse-monitoring logs — content sent to AI providers may be retained by them for abuse monitoring: OpenAI retains embeddings-API data for up to 30 days; Google retains paid Gemini/Vertex prompts, context, and outputs for up to 55 days. See Section 4.
- Security and audit logs — these record events (such as memory actions, sharing, and connector authorizations) using identifiers and event metadata rather than your memory content, and are retained as long as necessary for security, fraud prevention, and legal compliance.
Your Privacy Controls and Rights
7.1 Controls in the Service. Through the EchoMem privacy dashboard and related controls, you can, where supported, view and search your memories, see each memory’s visibility, correct or edit memories, delete memories, export memories, and manage sharing and connectors.
7.2 Deletion. Echo stores source content, extracted memories, embeddings, indexes, visibility records, and logs separately, so a given deletion action does not remove every related item:
- Deleting a memory removes that memory and the embeddings and indexes derived from it. Because a single source conversation may relate to multiple memories, deleting a memory does not delete the source conversation it was extracted from.
- Deleting your account runs a cascaded deletion process that removes, from active production systems, the data we hold about you, including your source conversations, extracted memories, embeddings and indexes, derived data, and sharing and visibility records.
- Content you shared with others — deleting your account does not delete messages or memories you previously shared with or sent to other users; that content may remain in their accounts after your deletion.
- Deleting a specific source. To delete an individual source conversation without deleting your whole account, contact us at [email protected] and we will delete it within the timeframe required by applicable law (generally within 45 days).
- Backups and logs. Residual copies may persist in backups, and security and audit logs follow separate schedules (Section 6).
7.3 Export. You can export your memories, and where applicable your source content and settings, in a machine-readable format.
7.4 Your U.S. state privacy rights. Depending on your state of residence, you may have some or all of the following rights regarding your personal information. We honor these rights for residents of states that provide them.
- Access / know — to confirm whether we process your personal information and to obtain a copy of it, along with information about how we use and share it.
- Correct — to correct inaccurate personal information.
- Delete — to request deletion of your personal information, subject to legal exceptions.
- Portability — to obtain a copy of your personal information in a portable, machine-readable format.
- Opt out — to opt out of the “sale” or “sharing” of your personal information and of targeted advertising. As described in Section 3, Echo does not sell or share your personal information or use it for targeted advertising, so there is nothing for you to opt out of in this respect.
- Limit use of sensitive information — where applicable, to limit the use of sensitive personal information to what is necessary to provide the Service.
- Non-discrimination — we will not discriminate or retaliate against you for exercising any of these rights.
How to exercise your rights. You can exercise many of these rights directly through the in-product privacy controls (Section 7.1). You may also submit a request by contacting us at [email protected] or at the mailing address in the Contact section. We will verify your identity before acting on your request, and we may decline or limit a request as permitted by law.
Authorized agents. You may designate an authorized agent to submit a request on your behalf. We will ask the agent to provide proof that you authorized them to act for you (such as written, signed permission), and we may also ask you to verify your own identity directly with us and to confirm that you gave the agent permission. This helps us protect your account against unauthorized requests.
Appeals. If we decline your request, you may appeal by emailing us at [email protected] with the subject line “Privacy Appeal.” We will review your appeal and respond within the time required by applicable law, and in any event within 45 days, explaining the outcome. If your appeal is denied, we will also tell you how to contact your state attorney general if you wish to raise a concern.
Timing. We respond to and act on your request within the timeframe required by applicable law (generally within 45 days, extendable when reasonably necessary, with notice to you). Deletion requests are acted on promptly; residual copies in backups and logs expire on the schedules described in Section 6.
Cookies, Analytics, and Diagnostics
Essential cookies. Echo uses cookies that are necessary for the Service to function, including authentication and session cookies (provided through our infrastructure provider) and a functional token cookie used to protect our media assets from unauthorized use. These do not require consent and are not used to track you.
Research-page analytics (consent-based). On our public research pages, with your consent, we use first-party cookies and usage analytics — such as which pages are viewed and how they are navigated — through our analytics provider to understand how these pages are used. This analytics runs only after you consent through our banner, and only on our production website. You can decline through the banner, in which case this analytics does not run. If you accept and later wish to withdraw your consent, you can do so by clearing the consent cookie through your browser settings.
Product analytics and diagnostics. Across the Chrome Extension, the npm/MCP tools, the web platform, and Echo Chat, we use product analytics (through our analytics provider, Amplitude) to understand usage and improve the Service, and in Echo Chat we use Google Firebase Crashlytics to collect crash and error diagnostics and improve stability; Crashlytics receives crash/diagnostic data only (no memory content or precise identifiers) and retains it for approximately 90 days (Firebase default). Our public memory-graph features use first-party presence and interaction data to show activity on shared graphs; this information stays within Echo and is not shared with third-party advertisers. These analytics and diagnostics receive usage and diagnostic metadata only, not your memory content.
Cloudflare infrastructure and cookieless analytics. We use Cloudflare to provide domain name services, security, content delivery, reverse-proxy services, traffic analysis, and website performance analytics. Because Cloudflare operates as a reverse proxy in front of our application, it may process network and request information such as IP addresses, request headers, requested URLs and paths, timestamps, browser and device information, and security signals, as well as content transmitted through proxied endpoints. Cloudflare Web Analytics uses a JavaScript beacon to collect aggregated page-view and performance metrics without analytics cookies or local storage and without tracking visitors over time. This cookieless analytics is separate from the consent-based analytics used on our research pages. Cloudflare processes this information as a service provider under a data-processing agreement.
No advertising trackers. Echo does not use advertising or marketing pixels or advertising cookies on any surface, and does not use analytics or diagnostics data for cross-context behavioral advertising. We use Google Fonts and search-engine site-verification tags for site functionality and SEO; these are not used to track you.
Your choices. You can control cookies through your browser settings and, for research-page analytics, through our consent banner. Blocking essential cookies may affect how the Service works.
Security
Echo uses administrative, technical, and organizational measures designed to protect personal information, including encryption of your content in transit, access controls and least-privilege principles, audit logging, secure credential handling, incident response, and vendor management.
Encryption and readable processing. Any at-rest encryption feature protects stored content in our database; it is not end-to-end encryption. To create memories, content you direct Echo to process — including a coding session’s user and assistant text uploaded through Context HUD renewal — is processed in readable form by Echo and by third-party AI providers.
Encryption at rest is optional. Your memories and source conversations are stored in our secured database, which uses access controls and other protections. You can also enable optional encryption for an additional layer of protection: if you turn it on, you set a key, and your memories and source conversations are encrypted at rest using a key derived from it. Encryption is not enabled by default, so you need to turn it on to use it. Enabling encryption does not prevent Echo or third-party AI providers from processing your content in readable form to provide the Service.
As described in Section 4, your content is processed in readable form by Echo and by third-party AI providers in order to create and organize memories. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
If we become aware of a security incident affecting your personal information, we will take reasonable steps to identify the cause, mitigate harm, and prevent recurrence, and will provide any notifications required by applicable law.
US-Directed Service
Echo is based in the United States and the Service is directed to and intended for users located in the United States. We and our service providers process information in the United States. We do not offer or direct the Service to users in the European Economic Area, the United Kingdom, or other regions outside the United States, and the Service is not intended for use by individuals located there.
If you access the Service from outside the United States, you do so on your own initiative and are responsible for compliance with local law, and your information will be transferred to and processed in the United States, where privacy laws may differ from those in your location.
Children’s Privacy
The Service is intended only for adults at least 18 years old. We do not knowingly collect personal information from anyone under 18, and you may not use Echo to store, process, or share personal information from or about anyone under 18. If we obtain actual knowledge that a user is under 18, we may suspend the account and initiate deletion of associated data. If you believe someone under 18 has provided us personal information, please contact us.
Changes to This Privacy Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by updating the date above and posting the revised Policy or by other appropriate means. Your continued use of the Service after the effective date indicates your acknowledgment of the changes.
How to Contact Us
Contact. Iditor, Inc. (d/b/a Echo). Email: [email protected]. Mailing address: 39 Bruton Street, Apt 705, San Francisco, CA 94130, USA. You can reach us at this email or address for privacy questions and to exercise your rights.