IDITOR, INC. · d/b/a ECHO

Version 1.0 — Effective July 16, 2026

Terms of Use

Platform Access and Usage Agreement

This Platform Access and Usage Agreement (the “Agreement” or “Terms”) is a binding agreement between Iditor, Inc., d/b/a Echo (“Echo,” “we,” “us,” or “our”), and the individual accepting these Terms (“you” or “User”). These Terms govern your access to and use of the Echo memory system and all related interfaces described below.

Please read these Terms carefully. They include important provisions about how disputes are handled (Section 20) and disclaimers and liability limits (Sections 16–17) that limit our responsibility to you.

Acceptance of Terms

You accept these Terms by doing any of the following: creating an Echo account; installing or using the Echo Chrome Extension; installing or using the Echo npm package, MCP server, or Echo Context HUD; using Echo Chat; or otherwise accessing or using any part of the Service. If you do not agree, do not use the Service.

Certain surfaces require you to affirmatively accept these Terms, the Privacy Policy, and the Memory Usage Terms, and to confirm you meet the age requirement in Section 2, before you can create durable memories. Your acceptance is recorded. We may present updated acceptance requirements as the Service changes.

These Terms govern individual, personal use of the Service. They do not authorize use of the Service on behalf of, or for the benefit of, any organization, or deployment of the Service across multiple users, an enterprise, or a team. Organizational, enterprise, team, and other multi-user use requires a separate written agreement with Echo, which will govern that use. If you purport to accept these Terms on behalf of an organization, you represent that you are authorized to bind it; however, until a separate written agreement is executed, these consumer Terms do not extend enterprise, administrative, data-processing, or organizational rights or obligations, and Echo does not act as a processor of any organization’s data under these Terms alone.

Eligibility

The Service is intended solely for adults. You must be at least 18 years old, or the age of majority in your jurisdiction if higher, and legally able to enter into a binding contract. By using the Service, you represent and warrant that you meet these requirements. This age requirement is a condition of use, and you may not use the Service if you do not meet it.

The Service is not directed to children, and we do not knowingly collect personal information from anyone under 18. If we obtain actual knowledge that a User is under 18, we may suspend the account and initiate deletion of associated data in accordance with our policies.

You may not use the Service to store, process, or share personal information from or about any person under 18.

Description of the Service

Echo is a user-directed, cross-platform memory system that helps you store, organize, extract, index, search, retrieve, and synchronize “memories” across supported tools and interfaces. Depending on the components you choose to use, the Service may be made available through a Chrome Extension, an npm package (which includes the Echo MCP server and an optional local Context HUD), a Model Context Protocol (“MCP”) server, desktop integrations, a command-line interface, application programming interfaces, the EchoMem web platform, Echo Chat, and future integrations (collectively, the “Service”).

Echo Context HUD (companion to the npm package). The Echo npm package that provides the MCP server also includes an optional local Context HUD, a context-health companion that runs on your device. If you direct the Context HUD to renew a session, create a checkpoint, or perform another cloud-memory action, the content it transmits to Echo is processed and stored as User Content. How the Context HUD reads local files, what it monitors, and your controls are described in the Privacy Policy and the Memory Usage Terms.

You direct what the Service remembers. The Service acts on your instructions to access, capture, store, and retrieve content you choose to connect or provide. Different Echo surfaces obtain content in different ways. The Echo MCP tools read local files that your own tools (for example, coding assistants such as Codex CLI or Claude Code) write on your device, so you can turn them into memories; they do not sign in to or retrieve content from any third-party provider account. On surfaces where you connect a supported AI chat provider (such as the Chrome Extension or the web platform), the Service uses your existing session with that provider to access your conversations on your behalf, including reading your conversation list so you can choose what to extract. Echo does not independently sign in to or crawl third-party provider accounts. Some local components, including the Context HUD, continue monitoring supported files after you launch or enable them, until you quit or disable the applicable feature; hiding a Context HUD window does not by itself stop local monitoring. How these methods work, and your responsibilities for them, are described in Section 9 and in the Memory Usage Terms.

Some functionality depends on third-party platforms and services that Echo does not control. That functionality may change, degrade, or become unavailable, and Echo does not guarantee continued compatibility with any third-party platform. See Sections 9 and 11.

Echo is a memory hosting, synchronization, and retrieval service. It is not a publisher, professional adviser, identity verifier, medical provider, therapist, financial adviser, legal adviser, employer, educational decision-maker, insurer, credit provider, or safety-critical decision system.

User Accounts

To use most features you must create an account and provide accurate information. You are responsible for your account credentials, for all activity under your account, and for keeping your credentials confidential. You will promptly notify us of any unauthorized use or suspected compromise of your account.

Where you use programmatic access (for example, API keys or the MCP server), you are responsible for securing those credentials and for all activity conducted through them.

User Content

“User Content” means the content you provide to, capture through, or generate using the Service, including raw conversations, uploaded files, notes, prompts, outputs, extracted memories, and associated metadata.

Raw conversations. The Service may store raw source conversations. Raw conversation storage exists primarily to support product functionality — including re-extraction of memories, improving extraction for your own content, memory provenance, source references, and regenerating memories. Raw conversations are User Content, are stored to serve you, and you may delete them as described in Section 13.

Your responsibility. You are solely responsible for your User Content and for the consequences of storing, extracting, sharing, or relying on it. You represent and warrant that you have all rights, licenses, consents, notices, permissions, and lawful bases necessary to provide your User Content to Echo and to authorize Echo to process it as described in these Terms and the Privacy Policy. This includes content that involves other people — such as friends, family, colleagues, customers, students, patients, employees, or contractors.

Accuracy and reliance. Memories and other outputs the Service generates may be inaccurate, incomplete, outdated, duplicated, overcompressed, or missing context. Echo does not verify the accuracy, completeness, currency, legality, or reliability of User Content. You should independently verify memories before relying on them, and you may not use the Service as the sole basis for any material decision about any person, including legal, medical, financial, employment, housing, credit, insurance, educational, or safety-critical decisions.

License Granted by User

You retain all right, title, and interest in and to your User Content. Echo does not claim ownership of your User Content.

You grant Echo a limited, non-exclusive, worldwide, royalty-free license to host, store, reproduce, process, transmit, display, index, create embeddings from, perform memory extraction on, summarize, retrieve, and synchronize your User Content, and to enable sharing you direct, solely to the extent necessary to provide, maintain, secure, support, and improve the Service as described in these Terms and the Privacy Policy, and to provide the services you request. This license is revocable where technically feasible upon your deletion of the relevant User Content or termination of your account, subject to the retention terms in Section 13 and our standard backup practices.

Echo receives only the rights described above. Echo does not receive rights to your User Content for any purpose beyond operating and providing the Service to you and carrying out your requests.

Prohibited and Sensitive Data

The Service is designed to restrict the highest-risk data categories. Unless expressly supported under a separate written agreement, you will not upload, sync, or transmit to the Service: personal information from or about anyone under 18; protected health information; payment card data; passwords, API keys, secrets, or access tokens; government-issued identifiers; biometric data; or precise geolocation data. Echo may block, quarantine, redact, or decline to process content it identifies as falling into a restricted category. Coding-session logs can contain source code, credentials, secrets, and other sensitive information. Local analysis of an existing log on your device is distinct from your decision to transmit it: review the active session before using a feature that transmits it to Echo (such as Context HUD session renewal or checkpoint creation), and do not transmit restricted data listed in this Section.

Acceptable Use

You will not, and will not permit others to: (a) use the Service in violation of any applicable law or the rights of any third party; (b) upload restricted data in violation of Section 7; (c) reverse engineer, decompile, or attempt to derive the source code of the Service, except as permitted by law; (d) interfere with, disrupt, probe, or test the vulnerability of the Service or its infrastructure without our prior written consent; (e) access the Service through any unapproved interface, or circumvent usage, rate, or visibility limits; (f) use the Service to build a competing product or to conduct benchmarking for a competitor; (g) upload malicious code; (h) misrepresent your identity or your rights to any content; or (i) use the Service to store, process, or share content that is unlawful, or that infringes or violates the intellectual property, privacy, or other rights of others.

Third-Party Services and AI Providers

The Service may interact with third-party platforms, AI providers, and other services that you choose to connect or that are necessary to provide requested functionality (each, a “Third-Party Service”).

Independence. Echo is independent and is not affiliated with, endorsed by, sponsored by, or partnered with OpenAI, Anthropic, Google, Microsoft, or any other AI or platform provider. All third-party names and trademarks belong to their respective owners. Nothing in the Service or our materials should be read as implying an official integration or partnership with any such provider.

Local files (MCP tools and Context HUD). The Echo MCP tools read local files on your device — such as the session records your own coding tools (for example, Codex CLI or Claude Code) write locally — so you can turn them into memories. The MCP tools do not sign in to, or retrieve conversations from, any third-party provider account. The Context HUD separately monitors supported local coding-session files on a continuing basis while it is running to calculate context-health information, and can transmit the active session’s user and assistant text to Echo when you invoke a renewal or checkpoint action; like the MCP tools, it does not sign in to a third-party provider account to obtain those local files. Because these files can contain sensitive material such as source code or credentials, you are responsible for what you make available to them.

Connected providers (Chrome Extension and web). On surfaces where you connect your own third-party AI chat accounts, the Service uses your existing logged-in session with the provider to access your conversations on your behalf. The supported providers — OpenAI (ChatGPT), Anthropic (Claude), Google (Gemini), DeepSeek, xAI (Grok), and Perplexity — are independent of Echo, and Echo is not affiliated with, endorsed by, or partnered with them. You access only your own accounts and your own content, your use of each provider remains governed by that provider’s own terms, and you are solely responsible for your compliance with those terms. Your use of a provider is governed by that provider’s terms and privacy policy, not these Terms. A provider may restrict access, rate-limit, or suspend your account, and Echo is not responsible for those consequences.

No guarantee of compatibility. Third-Party Services are outside Echo’s control and may change, impose new restrictions, rate-limit, or become unavailable at any time. Echo does not warrant continued compatibility or availability, and the capture and connector tools are provided “as is.” Echo may suspend, limit, or disable any connector or capture mode, without notice, where necessary to comply with law, a provider’s policies or a change in a provider’s terms, security requirements, or operational needs, and without liability for doing so.

Risk allocation. Account suspension, data loss, rate-limiting, or other consequences imposed by a Third-Party Service are borne by you. Echo is not responsible for the acts or omissions of any Third-Party Service.

AI Services

The Service uses AI models — including third-party models — to extract, organize, and retrieve memories from content you provide. To do this, content you direct the Service to process may be transmitted to third-party AI providers for processing, as described in the Privacy Policy. Context-health scores shown by the Context HUD are calculated locally without sending the session to a third-party AI model. If you use the Context HUD to create a cloud checkpoint or memory, that content enters Echo’s AI-assisted extraction process described in this Section.

Outputs generated by AI models may be inaccurate or incomplete, may not be unique to you, and are not guaranteed to be free of third-party content or non-infringing. You are responsible for evaluating outputs before relying on them. Echo is not liable for the conduct of third-party AI providers.

Training. Echo does not use your raw conversations or extracted memories to train, fine-tune, or benchmark general-purpose AI models by default. Any such use would require your separate, affirmative consent, except for aggregated or de-identified data used consistently with the Privacy Policy and applicable law. In addition, the third-party AI providers Echo uses to process your content — OpenAI for embeddings and Google (paid Gemini / Vertex AI) for memory extraction — do not use that content to train their general-purpose models, under the terms of the paid services and tiers Echo uses, as described in the Privacy Policy.

Platform Access and Changes to the Service

Some features depend on third-party platforms and may be added, changed, limited, suspended, or removed at any time, with or without notice, including to maintain compliance with third-party terms or applicable law. Echo may also modify, add, or discontinue features of the Service generally. Echo will use reasonable efforts to communicate material changes where appropriate but is not obligated to maintain any particular feature, integration, or platform compatibility.

Privacy and Data Security

Our collection and use of personal information is described in the Echo Privacy Policy, which is incorporated into these Terms by reference. The Privacy Policy describes the Context HUD’s local-file categories, background monitoring and foreground-application observation, locally retained data, account and checkpoint-status requests, transcript upload on renewal, and the distinction between local scoring and cloud extraction.

Echo maintains administrative, technical, and organizational measures designed to protect User Content, including encryption in transit, access controls and least-privilege principles, audit logging, secure credential handling, incident response, and vendor management. Additional details are described in the Privacy Policy.

Optional encryption at rest. Your memories and source conversations are stored in our secured database, which uses access controls and other protections. You can also enable optional encryption for an additional layer of protection: if you turn it on, you set a key, and your memories and source conversations are encrypted at rest using a key derived from it. Encryption is not enabled by default, so you need to turn it on to use it.

In both cases, to create, extract, and organize memories, your content is processed in readable form by Echo and by third-party AI providers. As a result, the Service does not provide end-to-end encryption. Enabling encryption protects your memories and source conversations at rest in our database; it does not prevent Echo or third-party AI providers from processing your content in readable form to provide the Service. Content transmitted to third-party AI providers is processed under their terms, as described in the Privacy Policy.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

If we become aware of a security incident affecting your personal information, we will take reasonable steps to address it and provide any notifications required by applicable law.

Data Storage, Retention, Deletion, and Export

User controls. You can view, search, correct, delete, and export your memories through supported interfaces, and you can request deletion of your account and associated data through supported interfaces. You can delete your account from the surfaces that offer account deletion, including the Echo website, the Echo Chrome Extension, and Echo Chat.

What account deletion removes. When you delete your account, Echo runs a cascaded deletion process that removes, from active production systems, the data we hold about you, including raw source conversations, extracted memories, embeddings and vector indexes, associated derived data, and sharing and visibility records.

Content you shared with others. Deleting your account does not delete messages or memories you previously shared with or sent to other users. Content already delivered to another user — including messages in paired or friend exchanges — may remain in that user’s account after your deletion.

Retention. When you delete your account or make a verified deletion request, Echo acts on it promptly — the deletion is effected without undue delay, and in any case within the timeframe required by applicable law (generally within 45 days) — removing your memories, source conversations, embeddings, and associated account records from active production systems, except where limited retention is required by law or for security, fraud-prevention, or dispute-resolution. Residual copies may persist for limited periods in encrypted backups and provider logs before automatic expiration, and security and audit logs follow separate schedules, as described in the Privacy Policy. Account deletion removes data held in Echo’s active production systems as described above. It may not remove files, preferences, cached checkpoint or carryover text, or other artifacts stored locally on your device by the Echo npm package, MCP server, or Context HUD. You can stop the Context HUD, disable launch at login, and remove local Echo files using supported controls or removal instructions.

Export. You can export your memories, and where applicable your raw conversations and settings, in a machine-readable format through supported interfaces.

Intellectual Property

As between you and Echo, Echo owns all right, title, and interest in and to the Service and all related software, models, interfaces, documentation, and technology, including all improvements and derivatives, excluding your User Content. No rights are granted to you except as expressly stated in these Terms. Echo’s names, logos, and marks may not be used without our prior written permission.

Copyright complaints (DMCA). Echo respects intellectual-property rights and responds to notices of alleged copyright infringement concerning content made available through the Service, including memories or other content that users choose to share publicly or with others. If you believe content accessible through the Service infringes your copyright, send a written notice to our designated agent that includes: (a) your physical or electronic signature; (b) identification of the copyrighted work claimed to be infringed; (c) identification of the material claimed to be infringing and information reasonably sufficient to let us locate it; (d) your contact information; (e) a statement that you have a good-faith belief the use is not authorized by the copyright owner, its agent, or the law; and (f) a statement, under penalty of perjury, that the information in your notice is accurate and that you are the copyright owner or authorized to act on the owner’s behalf.

Designated agent. Copyright Agent, Iditor, Inc. (d/b/a Echo). Email: [email protected]. Mailing address: 39 Bruton Street, Apt 705, San Francisco, CA 94130, USA.

Counter-notice and repeat infringers. If material you posted was removed or disabled, you may submit a counter-notice with the information required by 17 U.S.C. § 512(g). We may, in appropriate circumstances and at our discretion, disable or terminate the accounts of users who are repeat infringers.

Feedback

If you provide feedback, suggestions, or ideas about the Service, you grant Echo a perpetual, irrevocable, worldwide, royalty-free license to use them without restriction or obligation to you. We will not identify you as the source without your permission.

Disclaimers

TO THE MAXIMUM EXTENT PERMITTED BY LAW, THE SERVICE IS PROVIDED “AS IS” AND “AS AVAILABLE,” WITH ALL FAULTS AND WITHOUT WARRANTIES OF ANY KIND, WHETHER EXPRESS, IMPLIED, OR STATUTORY, INCLUDING IMPLIED WARRANTIES OF MERCHANTABILITY, FITNESS FOR A PARTICULAR PURPOSE, TITLE, AND NON-INFRINGEMENT. ECHO DOES NOT WARRANT THAT THE SERVICE WILL BE UNINTERRUPTED, ERROR-FREE, OR SECURE, THAT MEMORIES OR OUTPUTS WILL BE ACCURATE, COMPLETE, OR RELIABLE, OR THAT THE SERVICE WILL REMAIN COMPATIBLE WITH ANY THIRD-PARTY PLATFORM. YOU ARE SOLELY RESPONSIBLE FOR EVALUATING AND VERIFYING MEMORIES AND OUTPUTS BEFORE RELYING ON THEM. ECHO IS NOT RESPONSIBLE FOR THE CONDUCT OF ANY THIRD PARTY OR THIRD-PARTY SERVICE, AND THE RISK ARISING FROM ANY THIRD PARTY RESTS WITH YOU.

Limitation of Liability

TO THE MAXIMUM EXTENT PERMITTED BY LAW, ECHO WILL NOT BE LIABLE FOR ANY INDIRECT, INCIDENTAL, SPECIAL, CONSEQUENTIAL, EXEMPLARY, OR PUNITIVE DAMAGES, OR FOR ANY LOST PROFITS, LOST DATA, OR LOSS OF GOODWILL, ARISING OUT OF OR RELATING TO THESE TERMS OR THE SERVICE, EVEN IF ADVISED OF THE POSSIBILITY OF SUCH DAMAGES.

ECHO’S TOTAL AGGREGATE LIABILITY ARISING OUT OF OR RELATING TO THESE TERMS OR THE SERVICE WILL NOT EXCEED THE GREATER OF (A) THE AMOUNTS YOU PAID ECHO FOR THE SERVICE IN THE TWELVE (12) MONTHS PRECEDING THE EVENT GIVING RISE TO THE CLAIM, OR (B) ONE HUNDRED U.S. DOLLARS (US $100).

THESE LIMITATIONS DO NOT APPLY TO LIABILITIES THAT CANNOT BE LIMITED OR EXCLUDED BY LAW. THESE LIMITATIONS ARE A FUNDAMENTAL BASIS OF THE BARGAIN BETWEEN YOU AND ECHO.

Indemnification

You will indemnify, defend, and hold harmless Echo and its officers, directors, employees, and agents from and against any third-party claims, damages, losses, liabilities, costs, and expenses (including reasonable attorneys’ fees) arising out of or relating to: (a) your User Content; (b) your use of the Service; (c) your violation of these Terms or applicable law; (d) your violation of any third party’s rights, including intellectual property or privacy rights; (e) your upload of restricted data in violation of Section 7; or (f) your use of, or failure to comply with the terms of, any Third-Party Service.

Suspension and Termination

You may stop using the Service and delete your account at any time through supported interfaces. Ending your account does not by itself stop an already-installed local Context HUD process or remove local Echo files; to fully stop local operation, quit the Context HUD, disable launch at login (for example, echomem-hud autostart off), and uninstall or remove the local Echo package and its files. Echo may suspend or terminate your access, in whole or in part, with or without notice, if we reasonably believe you have violated these Terms or applicable law, if your use poses a risk to the security, integrity, or availability of the Service or to others, if required to comply with a Third-Party Service’s terms or a legal obligation, or if your account is inactive or otherwise as described in these Terms.

On termination, the licenses you grant and the rights you receive end, and you will stop using the Service. Deletion of your data following termination is handled as described in Section 13 and the Privacy Policy. Sections that by their nature should survive — including Sections 5–7, 10, 12–18, 20, and 21 — survive termination.

Governing Law and Dispute Resolution

Governing law. These Terms are governed by the laws of the State of California, without regard to its conflict-of-law principles.

US-directed Service; venue. The Service is directed to and intended for users located in the United States. You and Echo submit to the exclusive jurisdiction and venue of the state and federal courts located in San Francisco, California, for any dispute arising out of or relating to these Terms or the Service.

Informal resolution first. Before initiating any formal proceeding, you agree to first give Echo written notice describing the dispute (at [email protected] or the mailing address in the Contact section), and the parties will attempt in good faith to resolve it for thirty (30) days after that notice.

Small claims. Either party may bring an individual claim in a small-claims court of competent jurisdiction if the claim qualifies.

General Provisions

Changes to these Terms. We may modify these Terms from time to time. If we make material changes, we will provide notice by updating the effective date and posting the revised Terms, or by other appropriate means. Changes are effective when posted unless stated otherwise. Your continued use of the Service after the effective date constitutes acceptance. Where required, we will seek renewed acceptance.

Assignment. You may not assign these Terms without our prior written consent. We may assign these Terms in connection with a merger, acquisition, reorganization, or sale of assets.

Entire agreement; severability; waiver. These Terms, together with the Privacy Policy, the Memory Usage Terms, and any separate written agreement between you and Echo, are the entire agreement regarding the Service. If any provision is held unenforceable, the remaining provisions remain in effect. Our failure to enforce a provision is not a waiver.

Independent contractors; no third-party beneficiaries. The parties are independent contractors. These Terms create no third-party beneficiary rights.

Export and sanctions compliance. You represent that you are not located in, and will not use the Service in violation of, any applicable export-control or sanctions laws, and that you are not a restricted or prohibited party under such laws.

“Including.” As used in these Terms, “including” means “including but not limited to.”

Contact Information

Contact. Iditor, Inc. (d/b/a Echo). Email: [email protected]. Mailing address: 39 Bruton Street, Apt 705, San Francisco, CA 94130, USA.