Privacy Policy

Last updated: March 18, 2026

1. Introduction

At Echoes, we believe your private thoughts deserve sanctuary. This Privacy Policy explains how we collect, use, and protect your information when you use our service. We don't just comply with privacy laws — we honor the trust you place in us by keeping your words safe.

2. Information We Collect

  • Account information — email, name (optional), and secure password
  • Your echoes — the letters, voice notes, and time capsules you create
  • Usage data — how you interact with the app ( anonymized )
  • Payment information — processed securely through Stripe (we never see your card details)

3. How We Use Your Information

We use your information to:

  • Deliver your echoes to intended recipients
  • Secure your account and improve our service
  • Process payments through Stripe
  • Send you updates about scheduled deliveries

That's it. We don't sell your data. We don't use it for ads. We don't share it with third parties except as necessary to deliver your echoes.

4. Data Security

We use industry-standard encryption (AES-256) for data at rest and TLS 1.3 for data in transit. Your passwords are hashed using bcrypt. All API keys are stored encrypted. We retain usage logs for 30 days maximum, stripped of PII.

5. Your Rights

  • Access — Request a copy of your data
  • Delete — Request deletion of your account and all echoes
  • Export — Download your data in JSON format
  • Control — Manage notification preferences anytime

To exercise these rights, contact us at privacy@heartechoes.io

6. Cookies & Tracking

We use essential cookies only — to keep you logged in and remember your preferences. No advertising cookies. No tracking across other sites.

7. Data Retention

Your echoes remain in our secure vault until their scheduled delivery date. After delivery, you can choose to delete them or keep them stored. If you delete your account, all data is permanently removed within 30 days.

8. Children's Privacy

Echoes is not intended for children under 13. We do not knowingly collect information from children.

9. Changes to This Policy

We will notify you of any material changes to this policy via email at least 30 days before they take effect. Your continued use of Echoes after changes constitutes acceptance.

10. Contact Us

Questions? We're here.

Email: privacy@heartechoes.io