Privacy Policy
Last updated: 18 July 2026
Echo turns your speech into text. This policy covers Echo on desktop and Echo for iOS and Android, and says exactly what data that involves, where it goes, and how long it stays. Echo does not read your screen, log keystrokes, or take screenshots.
Controller (Verantwortlicher)
Echo is made by Ubinexlabs Pvt Ltd, Mumbai, India. Contact: support@goechoo.com
Supervisory authority
EU users may complain to their local data protection authority. In Germany: the Bundesbeauftragte für den Datenschutz und die Informationsfreiheit (BfDI), or the authority of their Bundesland.
What we collect
Account
Your email address and name, from Google Sign-In. The scope requested is openid email profile — there is no access to Gmail, Drive or Calendar. We never see your Google password. On mobile, your session tokens are stored in the iOS Keychain / Android Keystore on your device; on desktop, see Tokens below.
Audio
When you dictate, the recording is sent to our server for transcription, and from there to the Whisper model (whisper-large-v3-turbo) operated by Groq, Inc. Audio is uploaded only while you are actively dictating — while you hold the record button, or between the tap that starts and the tap that stops. Echo does not listen in the background, has no wake word, and does not record when you have not asked it to. If dictation captures something you did not intend, that audio is still deleted immediately after transcription — never retained, reviewed, or used for training.
Operational data
The length of a dictation, a timestamp, and error codes, tied to your account. Your email/account also counts your daily usage against a quota. This applies whenever you use cloud transcription — on desktop and on mobile alike. We do not store the content of the transcript.
What we do not collect
- No analytics, telemetry or usage tracking. None at all.
- No crash reporting, no third-party trackers.
- No advertising, and no sale or sharing of your data with advertisers.
- No screenshots. There is no screen-capture code in the product.
- No keystroke logging. On desktop, Echo uses a global keyboard hook so your chosen hotkey works in any app; it inspects key presses only to detect that hotkey and stores none of them.
- Your dictation history and transcripts — they stay on your device.
- Your notes and custom dictionary — they stay on your device.
What happens to your audio
Your audio is processed for transcription and is not retained afterwards.
- On our server: the audio is received, wrapped for the transcription request, forwarded to Groq, and discarded. Our backend writes no audio and no transcript text to disk or to any database; it records only operational metadata (the length of the clip, a timestamp, a status code, and processing latency). This is confirmed against the echo-api source.
- On Groq (sub-processor): Groq performs the speech-to-text and, if grammar cleanup is on, the text polish.
On Echo for iOS and Android
Where your transcripts live
Your transcripts are stored in a database on your phone and nowhere else. If the grammar-cleanup feature (“AI polish”) is on, the transcribed text passes through our server to be cleaned up and is discarded there immediately after. Turn it off in Settings and your text never leaves the device after transcription. On our servers we keep no transcripts at all; on your phone you choose the retention window — 7, 30, 90 days, forever, or don’t save at all, defaulting to 30 days. Choosing a shorter window deletes anything already outside it straight away.
Permissions Echo asks for
| Permission | Platform | Required? | What it’s for |
|---|---|---|---|
| Microphone | iOS & Android | Yes | To hear you. Nothing works without it. |
| Display over other apps | Android | No | Draws the floating record button over other apps. |
| Accessibility service | Android | No | Places your transcribed text into the field you were typing in. |
| Notifications | Android 13+ | No | Only to tell you the floating button stopped working. Never for marketing. |
Every permission except the microphone is optional, and declining any of them leaves Echo working. Echo does not request location, contacts, camera, photos, calendar, or Bluetooth at all.
About the Android accessibility service: it reads which text field currently has input focus — nothing else. It does not read the contents of that field, any other field, the rest of the screen, or anything you type. It exists for one reason: so the text lands in the box you were already typing in. If you would rather not grant it, the Echo keyboard does the same job through the standard keyboard mechanism, and no accessibility permission is needed.
On Echo for desktop
What stays on your computer
These never leave your device:
- Dictation history (SQLite, in the app’s user-data folder)
- Notes
- Custom dictionary
- Settings
Retention setting: 7, 30, 90 days, forever, or off. Default 30 days.
The record indicator
For fast repeat dictations, Echo keeps the microphone open for a short time (about 20 seconds) after you finish, then releases it fully. During that window Echo is not capturing or sending any audio; your operating system’s microphone indicator may stay on until the microphone is released.
Tokens
The access token lives in memory for 15 minutes. The refresh token is encrypted in the OS keychain (safeStorage). Neither is ever stored in plaintext.
Legal basis (GDPR Art. 6)
| Processing | Basis |
|---|---|
| Audio transcription | Art. 6(1)(b) — performance of a contract you asked for |
| Account (email, name) | Art. 6(1)(b) — performance of a contract |
| Payment | Art. 6(1)(b) and Art. 6(1)(c) — performance of a contract and legal obligation (tax records) |
| Error logs and usage quota | Art. 6(1)(f) — legitimate interest in running the service and preventing abuse |
There is no consent-based processing, because there is no tracking to consent to.
Sub-processors
| Who | What | Where | Transfer basis |
|---|---|---|---|
| Groq, Inc. | Speech-to-text, grammar polish | USA | EU SCCs (2021/914) via Groq DPA |
| Google LLC | Sign-in only | USA | EU SCCs / DPF |
| Amazon Web Services, Inc. | Backend hosting | Asia Pacific (Mumbai), India | EU SCCs + Transfer Impact Assessment |
| Lemon Squeezy | Payment (Merchant of Record, desktop) | USA | EU SCCs |
International transfers (GDPR Art. 44+)
Your audio leaves the EU. Plainly:
Groq (USA): the EU Standard Contractual Clauses (Commission Decision 2021/914) form part of Groq’s DPA. The Irish DPC is the relevant supervisory authority.
Sending your voice to a transcription model is necessary to provide the service you asked for — there is no version of Echo that transcribes your speech without your speech going somewhere. If you would rather your transcribed text not pass through our server, turn off AI polish in Settings; your audio is still transcribed, but the resulting text then stays on your device.
Your rights
Access, correction, deletion, portability, restriction, and objection. Write to support@goechoo.com and we answer within 30 days.
To delete your account and the usage records tied to your email, write to the same address. Everything is deleted within 30 days. Your transcripts were never ours to delete, because they are on your device — delete them yourself from your history, or set retention to “don’t save”.
Children
Echo is not directed at children, and we do not knowingly collect data from them.
Changes
If we change what data Echo collects or where it goes, we will update this page and the date above. Material changes are announced in the app before they take effect.