Privacy Policy
Last updated: 1 September 2026
Go Echoo turns your speech into text. This policy covers Go Echoo on desktop and Go Echoo for iOS and Android, and says exactly what data that involves, where it goes, and how long it stays. Go Echoo does not read your screen, log keystrokes, or take screenshots.
Controller (Verantwortlicher)
Go Echoo is made by Ubinexlabs Pvt Ltd, Mumbai, India. Contact: support@goechoo.com
Supervisory authority
EU users may complain to their local data protection authority. In Germany: the Bundesbeauftragte für den Datenschutz und die Informationsfreiheit (BfDI), or the authority of their Bundesland.
What we collect
Account
Your email address and name, from Google Sign-In. The scope requested is openid email profile — there is no access to Gmail, Drive or Calendar. We never see your Google password. On mobile, your session tokens are stored in the iOS Keychain / Android Keystore on your device; on desktop, see Tokens below.
Audio
When you dictate, the recording travels to our server and on to our speech-to-text provider, purely to be turned into text. Audio is uploaded only while you are actively dictating — while you hold the record button, or between the tap that starts and the tap that stops. Go Echoo has no wake word and never records when you have not asked it to. If a dictation captures something you did not intend, that audio is still deleted the moment transcription finishes — never kept, never reviewed, never repurposed.
On iPhone, the microphone can stay open in the background for the length of a dictation session you start and choose the duration of. That is the one place in Go Echoo where the microphone is live while the app is not in front of you, it is described in full under “Flow Sessions” below, and it changes nothing about what happens to the audio: it is still only uploaded while you are dictating, still transcribed, still discarded. On Android the microphone is never open in the background.
Operational data
The length of a dictation, a timestamp, and error codes, tied to your account. Your email/account also counts your daily usage against a quota. This applies whenever you use cloud transcription — on desktop and on mobile alike. We do not store the content of the transcript. The one exception is cloud sync, which is off unless you switch it on and which has its own section below.
What we do not collect
- No analytics, telemetry or usage tracking in the product. None at all. (This website is separate — see “This website” below.)
- No crash reporting, and no third-party trackers in the product.
- No advertising, and no sale or sharing of your data with advertisers.
- No screenshots. There is no screen-capture code in the product.
- No keystroke logging. On desktop, Go Echoo uses a global keyboard hook so your chosen hotkey works in any app; it inspects key presses only to detect that hotkey and stores none of them.
- Your dictation history and transcripts — they stay on your device unless you switch on cloud sync, which is off by default. See “Cloud sync” below.
- Your notes and custom dictionary — the same: on your device, and on our servers only if you switch on cloud sync.
This website
Everything above is about the Go Echoo app. This website is a separate thing, and it does use analytics — but only if you agree to it. Before you answer the banner, no analytics script is loaded, no request is made to Google, and no analytics cookie is set. If you decline, that stays true.
If you agree, we load Google Analytics 4 to see which pages get read. It sets cookies in your browser (_ga and one named for our measurement stream) and sends your IP address, the page you are on and your approximate location to Google Ireland Limited, which may transfer it to Google LLC in the United States under the EU–US Data Privacy Framework. We ask Google to shorten your IP address. The legal basis is your consent, GDPR Art. 6(1)(a) and §25(1) TTDSG.
You can change your mind at any time: “Cookie choice” at the bottom of any page reopens the banner. Withdrawing switches analytics off and deletes the cookies it set. Withdrawing does not make the measuring we already did unlawful, but it stops any more of it.
What this site stores without asking
- Your language choice, so the site serves the language you picked.
- A country hint, written by our own server, used only to suggest a language — never to change a price.
- Your light/dark preference.
- A session, if you have an account and are signed in.
These four are strictly necessary under §25(2) TTDSG: without them the site cannot do the thing you asked it to do. That is why they are disclosed here rather than put behind a switch.
What happens to your audio
Your audio is processed for transcription and is not retained afterwards.
- On our server: the audio is received, prepared for transcription, forwarded on, and discarded. Our backend writes no audio to disk or to any database — not on any setting, not ever. On the transcription path it writes no transcript text either; it records only operational metadata (the length of the clip, a timestamp, a status code, and processing latency). Cloud sync is the one path that stores text, and only if you switch it on.
- At our speech-to-text provider: they perform the transcription and, if grammar cleanup is on, the text polish, then discard the audio. We choose this provider on your behalf and may change it as the technology improves; whichever one is in use is bound by the same no-retention, no-training terms described here.
Cloud sync (off unless you switch it on)
Go Echoo can keep a copy of your dictation history, your notes and your custom dictionary on our servers, so that a reinstall or a new machine does not lose them: you sign in, and they come back. It is off by default. If you never switch it on, nothing in this section describes you and none of that data ever leaves your device.
What is synced
- Your dictation history, your notes, your custom dictionary, and a small set of preferences (your dictation languages, output language, cleanup mode, app language and theme) so a new device starts the way you left the old one. Hotkeys and other device-specific settings stay on the device.
- Not your audio. Recordings are still deleted the moment they are transcribed, whatever your sync setting. There is no version of this in which we keep your voice.
- Search stays on your device. Your history is searched in the local database on your machine; our server stores and expires what you send it, and never searches it.
How it is stored, exactly
The text of every synced dictation, and the title and body of every synced note, are encrypted before they are written to our database — AES-256-GCM, with a key that is not kept in that database. A stolen copy of the database on its own decrypts nothing.
The custom dictionary is the exception: it is stored unencrypted. Its entries are short spoken-to-written pairs — you say “gpt”, it writes “GPT” — and the server has to recognise the same spoken term twice so it does not duplicate it, which cannot be done over ciphertext that comes out different every time it is written. These are vocabulary hints rather than things you dictated, which is why we accepted that trade here and not for your history or your notes. We would rather name the exception than let “it is encrypted” cover something it does not.
Stored alongside a synced dictation, unencrypted, are the things that are not its content: when it was made, how long the recording was, and — if your device sends one — the name of the app you were dictating into.
This is encryption at rest, not end-to-end encryption. We hold the key, so we can technically decrypt your history and your notes. We do not read them. They are decrypted in two situations, and both of them are you asking: when your own device pulls its data back, and when you request a copy of your data. We spell this out because “encrypted” is usually left to imply “and we could not read it even if we wanted to” — which here would be untrue.
It is not end-to-end for a reason worth stating. Under end-to-end encryption, signing in on a new machine would not be enough to get your data back: you would need a recovery code, and the day you lost it your history would be gone permanently. Most people sign in with Google and have no passphrase for a key to be derived from. We chose the model where signing in is enough, and we are telling you what it costs.
How long the synced copy is kept
The retention window you choose in the app — 7, 30, 90 days, forever, or don’t save — applies to the copy on our servers, not only to the one on your device. Expired dictations are deleted from our database by a sweep that runs daily. Shortening the window purges whatever already falls outside it immediately, on our side as well as yours, because “gone by tomorrow” is not what a retention setting means. Notes and dictionary entries are not expired on a timer: you saved those deliberately, and they stay until you delete them.
Deleting a synced dictation or note erases its content from our database at once. A marker that the item existed and was deleted — an identifier and a date, no content — remains for up to 90 days so your other devices learn about the deletion, and is then removed as well.
Switching it off, and deleting your account
Switching sync off deletes everything we hold for you — history, notes and dictionary — in one operation. Setting retention to “don’t save” does the same. Deleting your account deletes it too: that path clears all three, whether the account is erased outright or anonymized because tax law requires the invoices to stay.
If you ask us for a copy of your data, the synced content is part of it, decrypted. It is personal data we hold, so it belongs in that export.
On Go Echoo for iOS and Android
Where your transcripts live
Your transcripts are stored in a database on your phone. If the grammar-cleanup feature (“AI polish”) is on, the transcribed text passes through our server to be cleaned up and is discarded there immediately after. Turn it off in Settings and — with cloud sync off, which is the default — your text never leaves the device after transcription. Unless you have switched sync on, we keep no transcripts on our servers at all, and the copy on your phone is the only one. On your phone you choose the retention window — 7, 30, 90 days, forever, or don’t save at all, defaulting to 30 days. Choosing a shorter window deletes anything already outside it straight away, on your phone and, if you sync, on our servers too.
Permissions Go Echoo asks for
| Permission | Platform | Required? | What it’s for |
|---|---|---|---|
| Microphone | iOS & Android | Yes | To hear you. Nothing works without it. Android: only while you are dictating. iPhone: also in the background during a Flow Session you started — see below. |
| Background audio | iOS | No | Keeps the microphone available to the keyboard during a Flow Session. Decline it and dictation still works from inside the app. |
| Display over other apps | Android | No | Draws the floating record button over other apps. |
| Accessibility service | Android | No | Places your transcribed text into the field you were typing in. |
| Notifications | Android 13+ | No | Only to tell you the floating button stopped working. Never for marketing. |
Every permission except the microphone is optional, and declining any of them leaves Go Echoo working. Go Echoo does not request location, contacts, camera, photos, calendar, or Bluetooth at all.
About the Android accessibility service: it reads which text field currently has input focus — nothing else. It does not read the contents of that field, any other field, the rest of the screen, or anything you type. It exists for one reason: so the text lands in the box you were already typing in. If you would rather not grant it, the Go Echoo keyboard does the same job through the standard keyboard mechanism, and no accessibility permission is needed.
Flow Sessions (iPhone only)
The Go Echoo keyboard on iPhone can dictate without you reopening the app first. To make that work, the app keeps the microphone active in the background for the length of a session — otherwise every dictation would mean switching to Go Echoo, starting it, and switching back. This is the only feature in Go Echoo that holds the microphone open while the app is not in front of you, and it exists on iPhone only. There is no equivalent on Android: there, the microphone records only while you are actively dictating, and never in the background.
- You start it, always. A session only begins when you start a dictation with Go Echoo open in front of you. It never starts on its own, never resumes by itself, and there is no setting that makes it automatic.
- You choose how long it lasts — 5 minutes, 15 minutes, 1 hour, or until you close the app.
- It ends by itself. When the window you chose runs out, the session is over and the microphone is released. You can also end it at any point before that by turning it off.
- You can see it the whole time. iOS shows its orange recording indicator for as long as the microphone is active, and that is outside our control — we cannot suppress it and would not want to. If the indicator is off, the microphone is not open.
What a session changes is when the microphone is <em>available</em>, not what happens to your voice. Audio is still uploaded only while you are actually dictating, still transcribed, and still discarded immediately afterwards — an open microphone is not a recording, and nothing is captured, buffered, or sent between one dictation and the next. Everything else in this policy applies unchanged during a session: no analytics, no screen reading, no keystroke logging, and no audio ever stored.
On Go Echoo for desktop
What stays on your computer
With cloud sync off — the default — none of these ever leaves your device:
- Dictation history (SQLite, in the app’s user-data folder)
- Notes
- Custom dictionary
- Settings
Retention setting: 7, 30, 90 days, forever, or off. Default 30 days. Switch cloud sync on and the history, notes and dictionary above are also copied to our servers, on the terms in the section above, along with the small preference set listed there (stored in plain form, like the dictionary — it contains language codes and mode names, never dictated content).
The record indicator
For fast repeat dictations, Go Echoo keeps the microphone open for a short time (about 20 seconds) after you finish, then releases it fully. During that window Go Echoo is not capturing or sending any audio; your operating system’s microphone indicator may stay on until the microphone is released.
Tokens
The access token lives in memory for 15 minutes. The refresh token is encrypted in the OS keychain (safeStorage). Neither is ever stored in plaintext.
Legal basis (GDPR Art. 6)
| Processing | Basis |
|---|---|
| Audio transcription | Art. 6(1)(b) — performance of a contract you asked for |
| Account (email, name) | Art. 6(1)(b) — performance of a contract |
| Payment | Art. 6(1)(b) and Art. 6(1)(c) — performance of a contract and legal obligation (tax records) |
| Error logs and usage quota | Art. 6(1)(f) — legitimate interest in running the service and preventing abuse |
| Cloud sync, if you switch it on | Art. 6(1)(a) — consent, withdrawn by switching sync off, which also deletes what we hold |
Cloud sync is the one kind of processing here that rests on your consent, and only if you switch it on. Nothing else does, because there is no tracking to consent to.
Sending your voice to a transcription service is necessary to provide the service you asked for — there is no version of Go Echoo that transcribes your speech without your speech going somewhere for processing. If you would rather your transcribed text not pass through our server, turn off AI polish in Settings; your audio is still transcribed, but the resulting text then stays on your device.
Your rights
Access, correction, deletion, portability, restriction, and objection. Write to support@goechoo.com and we answer within 30 days.
To delete your account and the usage records tied to your email, write to the same address. Everything is deleted within 30 days — and if you had switched on cloud sync, the copy of your history, notes and dictionary goes with it. The copies on your own device are still yours to remove: delete them from your history, or set retention to “don’t save”.
Children
Go Echoo is not directed at children, and we do not knowingly collect data from them.
Changes
If we change what data Go Echoo collects or where it goes, we will update this page and the date above. Material changes are announced in the app before they take effect.