Privacy policy
Last updated 14 September 2026 · Private beta
Echos gives you a receive-only email address that your AI assistants can read. This page says what we keep, why, for how long, who else touches it, and what you can do about it. It is written to be read, not to be skimmed past. If something here does not match what you see the product do, that is a bug — tell us at hello@echos.fyi.
Who we are
Echos is operated by Pudding App Inc, San Francisco, California, USA. Contact: hello@echos.fyi (an Echos address: it receives; replies come from a person’s own mailbox, because Echos never sends). We are a United States company, not established in the European Union; see “Your rights” for how we handle requests wherever you are.
What we collect, and why
- Your account. The email address you sign up with (your “contact email”), managed by our login provider Clerk, and the address you choose. We use the contact email to let you sign in and for nothing else.
- Mail sent to your Echos addresses. The message exactly as received (headers, text, HTML, attachments), plus what we derive from it: a cleaned text, a one-line summary, a category, a spam score, authentication results (SPF, DKIM, DMARC), text extracted from attachments, and text read from images. This is the service: it exists so that your assistants can read your mail.
- Who writes to you. A contact list built from senders — address, display name, when they first and last wrote, how many times. Derived from your mail; never typed in, never shared.
- Activity. A log of every call made against your mailbox: which assistant, which tool, which address, when, and the result. It never contains a subject or a body. It is how you see what your assistants did, and how we notice abuse.
- Billing. If you pay, Stripe holds your card and your invoices. We keep only Stripe’s customer and subscription identifiers and the plan you are on.
- Operational records. Usage counters (messages this month, storage, images read), rate-limit counters, and the health checks of our own systems.
We do not collect analytics, do not run advertising, and set no cookies beyond the ones our login provider needs to keep you signed in.
How long we keep mail
Every message has an expiry, and a nightly job permanently deletes what has expired — the raw message, its attachments, and every derived row, together. The longest a message can live is set by your plan: 90 days on Free, one year on Pro, three years on Dev. Within that, categories have shorter defaults because their value fades: verification codes one day, marketing seven, security alerts and newsletters thirty; receipts, travel, legal documents and personal mail keep the plan maximum. You can shorten any address’s retention (never lengthen past the plan), pin a message with the label keep, and on paid plans change the category defaults. Quarantined spam is deleted after thirty days regardless.
The activity log is kept 30 days on Free, one year on Pro, three years on Dev; security events (an agent connected, a grant changed, a login change) are kept for the life of the account. Nightly backups of the database are kept for 30 days and copies of raw mail for 35; deleted data therefore lingers in a backup for at most 35 days before it is gone everywhere.
Who can read your mail
Only what you allow. Every assistant, script or key you connect gets a grant you approve on a consent screen — which capabilities, which addresses — and can be paused or revoked at any moment from the dashboard. Every content-bearing response is marked as untrusted third-party text, so an assistant is told to treat what an email says as information, never as instructions. You can close any address to all assistants while still seeing it yourself.
We — the people who run Echos — do not read your mail. Our dashboard is designed so that it cannot show a subject or a body, and our operational tooling works with identifiers, counts and sender domains.
Who else processes your data
We run on a small number of providers, each for one job. None of them may use your data for their own purposes.
- Cloudflare — receives your mail, runs our code, stores raw messages and attachments, and reads text out of images (Workers AI). Its network is global; storage is in Cloudflare’s R2.
- Neon — our database (message metadata, derived text, accounts, the activity log), hosted in the United States (AWS us-west-2).
- Clerk — sign-in, passwords and passkeys, and every email you get about your account (verification, invitations, password resets). Echos itself never sends email.
- Stripe — payments. Card details never reach us.
- GitHub — runs our nightly database backup job.
A fuller inventory of what each provider holds is available on request.
What we never do
- Send email. Echos has no way to send mail — not to you, not to anyone, not on an assistant’s behalf.
- Sell, rent or share your data, or use your mail to train anything.
- Show anyone a subject or a body — not in the dashboard, not in our own tools.
Your rights, and where to exercise them
- Access and portability — Settings → Your data → “Export everything” gives you a zip of every message as received, every attachment, and a JSON index of everything we derived. Any time.
- Erasure — Settings → Danger zone → “Delete my account”. Assistants are cut off at once; within 24 hours every message, attachment, derived row and your login are gone. You can cancel until then. Backups purge within 35 days.
- Rectification — your contact email and login details are yours to change under Settings.
- Restriction and objection — pause all assistants, pause one, or close an address to assistants, all from the dashboard, all reversible.
- Anything else — write to hello@echos.fyi. We answer within 30 days, and we may ask you to confirm the request from your contact email first.
If you are in the EU/EEA, the UK or California, these are the rights those laws give you; we honour them for everyone.
California residents (CCPA/CPRA)
In the last twelve months we have collected the categories of personal information described above: identifiers (your contact email, handle, account and connection identifiers), the contents of mail sent to your addresses and what we derive from it, commercial information (your plan and Stripe identifiers), and internet activity limited to the activity log of calls against your mailbox. We collect it directly from you, from the senders of your mail, and from the assistants you connect. We use it only to provide the service, to secure it, and to bill you. We do not sell personal information and do not share it for cross-context behavioural advertising, and we have not done so in the last twelve months; there is no “Do Not Sell or Share” setting because there is nothing to opt out of. We do not use or disclose sensitive personal information other than to provide the service. You have the right to know, to delete, to correct, and to non-discrimination for exercising your rights; the sections above say where each is exercised, and an authorised agent may make a request on your behalf if we can verify the authorisation. We do not respond to “Do Not Track” signals because we do not track.
Children
Echos is not for anyone under 18, and we do not knowingly collect personal information from children under 13 (or under 16 where that is the threshold). If you believe a child has an account, tell us and we will delete it.
Where data lives, and transfers
Our servers and providers are in the United States (Cloudflare’s network is global, with storage in the US; Neon in AWS us-west-2; Clerk and Stripe in the US). If you use Echos from elsewhere, your data is transferred to and processed in the US under this policy. Mail you receive is, by its nature, sent to our servers by whoever sends it.
If something goes wrong
If we learn of a breach affecting your personal information we will tell you at your contact email and on the dashboard without undue delay, and tell regulators where the law requires.
Security
Mail is encrypted in transit and at rest. Assistants authenticate with OAuth or keys you can revoke; keys and tokens are stored as hashes. Every call is logged. Attachments that are programs are blocked before storage. Our own access is by named accounts with two-factor authentication.
Changes
When this page changes we update the date at the top and, for anything that narrows your rights, tell you on the dashboard before it takes effect.