Privacy Policy
Last updated October 7, 2026
Project Echo runs your day, your marketing and your customer list in one place. To do that it has to hold a lot of what matters to your business. This page says what we collect, why, who else touches it, and how to get it back or get rid of it.
The short version: your data is used to run Project Echo for you. We don’t sell it, we don’t use it for advertising, and you can have it deleted.
Who we are
Project Echo (“we,” “us”) provides the app at www.projectecho.app. Questions about this policy or your data go to hello@projectecho.app.
What we collect
Your account. Your name, email address, password (stored as a hash by our authentication provider, never readable by us), profile details you add, your company and team, and your plan.
What you put in. Tasks, notes and brain dumps; campaigns, scripts, posts, emails and other content; answers you give Echo in interviews and setup; your work preferences, such as working hours and time zone; files, images and videos you upload or record; and the contacts, leads and conversations you keep in the CRM.
Meetings and voice. When you record a meeting or a voice note, the audio is sent to a transcription provider and we keep the text: the transcript, a summary, and the action items drawn from it. We do not keep the meeting audio once it is transcribed. Meetings you import from a note-taker you have connected (such as Fathom or Otter) arrive as transcripts.
Signing in with Google or Facebook. We receive your name, email address and profile picture from that account.
Accounts you connect. Only when you connect them, and only what the connection needs:
- Google Calendar — access tokens, the calendar’s email address, your free/busy times and today’s events (titles, times, whether others are invited). See Google user data below.
- Gmail — if you connect it to send from your own address, access tokens and the email the integration sends and syncs.
- Meta (Facebook and Instagram) — access tokens, your ad account, Page and Instagram account IDs, ad performance, and the posts you publish through Project Echo. See also Data deletion.
- GoHighLevel — access tokens and the contacts, conversations and calendar data you choose to sync.
- AI assistants over MCP — if you create an access token in Settings, the assistant you give it to can read and change your Project Echo data on your behalf until you revoke it.
Payments. Card details go straight to Stripe. We see your plan, billing status and the last four digits of your card, never the full number.
Emails we send for you. When you send email to your contacts through Project Echo, we record deliveries, opens (with a tracking pixel) and unsubscribes so you can see results and so we honor opt-outs.
Running the service. Server logs, error reports, and basic request information (IP address, browser, pages requested), used to keep Project Echo working and secure. We use cookies and browser storage to keep you signed in and remember preferences. We do not use advertising or cross-site tracking cookies.
How we use it
- To run Project Echo for you: sort and schedule your tasks, write and publish your content, read your meetings, send the emails you ask for, and keep your CRM.
- To make Echo’s work about your business: what you tell it, and what it learns from your content and calls, shapes what it writes and suggests for you.
- To send you account and service messages, including the morning email, which you can turn off in Settings or from any of those emails.
- To bill you, prevent abuse, fix problems and keep the service secure.
- To meet legal obligations.
We don’t sell your personal information, share it for advertising, or use your content to train AI models of our own.
AI providers
Much of Project Echo is written or read by AI. To do that, the content involved in a request (a brief, a transcript, your notes, your interview answers) is sent to an AI provider, used to produce the result, and returned. We use the providers’ business APIs and send only what the request needs. Current providers: Anthropic (writing and reasoning), OpenAI (transcription and some generation), ElevenLabs (transcription and voice), Google Gemini, fal and Recraft (images), and Gamma (presentations).
Our team
A small number of Project Echo staff can open an account to support it, fix a problem, or keep the service secure. That access is temporary, ends on its own, and every time it happens is logged. Google user data is only ever viewed as the Google section below allows.
Who else handles your data
We use service providers who process data for us under contract, only to provide their service:
- Supabase — database, sign-in and file storage
- Railway — hosting
- Resend — sending email
- Stripe — payments
- Sentry — error reports
- Upstash — rate limiting
- The AI providers listed above
When you connect Google, Meta or GoHighLevel, or publish to them, data goes to those services under their own privacy policies. We may also disclose information if the law requires it, to protect people’s safety or our rights, or as part of a merger or sale of the business, in which case this policy continues to apply to your data.
Google user data
With your permission, Project Echo reads your Google Calendar to see when you are busy and what meetings you have today, so it can schedule tasks around them and remind you to record them. It writes events to your calendar only for tasks you schedule in Project Echo. If you separately connect Gmail, Project Echo uses it only to send and show email at your direction. Project Echo reads no other Google data.
Project Echo’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Google user data for advertising, do not sell it, do not let people read it except with your consent, for security, or where the law requires, and do not use it to develop or train generalized AI or machine-learning models. You can disconnect at any time in Settings or from your Google Account’s security page, and we delete the stored calendar tokens when you disconnect in Project Echo.
Contacts you store
When you add your customers, leads or contacts to Project Echo, we hold their information on your behalf, and you decide what happens to it. You are responsible for having the right to collect it and to contact them. If one of your contacts asks us about their data, we will point them to you.
How long we keep it
We keep your data while your account is open. If you delete something, it is deleted from the live service. If you close your account, we delete your data within 30 days, except what we must keep for legal, tax or billing reasons. Copies in backups are overwritten on their normal cycle.
Security
Data is encrypted in transit and at rest with our database provider. Each account’s data is separated by access rules in the database, and access tokens for connected services are kept on our servers. No system is perfectly secure; if a breach affects your data, we will tell you as the law requires.
Your choices and rights
- See, fix or export your data: most of it is in the app to view and edit. For a copy of everything, email hello@projectecho.app.
- Delete your data or account: email hello@projectecho.app and we will do it within 30 days.
- Disconnect Google, Meta or GoHighLevel at any time in Settings.
- Stop emails: turn off the morning email in Settings, or use the unsubscribe link in any email.
Depending on where you live (for example California, or the EU and UK), you may have further rights: to know what we hold, to object to or restrict processing, to data portability, and to complain to your data protection authority. Email hello@projectecho.app and we will answer within the time the law allows, without discriminating against you for asking. We process data to perform our contract with you, for our legitimate interest in running and securing the service, and with your consent for connected accounts.
Where data is processed
Project Echo is run from the United States, and our providers may process data in the United States and other countries. Where the law requires it, transfers are covered by appropriate safeguards such as standard contractual clauses.
Children
Project Echo is for businesses and isn’t meant for anyone under 16. We don’t knowingly collect data from children; if you believe we have, email hello@projectecho.app and we will delete it.
Changes
If we change this policy, we will update the date at the top. If the change is significant, we will tell you by email or in the app before it takes effect.
Contact
Email hello@projectecho.app with any question about your data or this policy.