Skip to content

Legal

Privacy

Effective 1 June 2026

This policy explains how Echo collects, uses, and protects your data. It applies to the marketing site, the dashboard, and the Slack agent.

01Who we are

Echo is a trading name of ALLIN1.APP LTD, a company registered in England and Wales. References to "we", "us", or "Echo" mean ALLIN1.APP LTD.

Our registered office is Varsity House, Falcon Court, Stockton-on-Tees TS18 3TS, United Kingdom.

If you have a question about this policy, write to [email protected] and reference your workspace name.

02What we collect

Account data: name, email, Slack workspace identifier, and authentication tokens for the tools you choose to connect.

Product data: the messages you send Echo, the files Echo produces, the tool calls it makes, and the credit balances on your workspace.

Operational data: logs, error reports, and basic device metadata required to keep Echo running.

03Signing in with Google

Echo offers "Sign in with Google" as a way to create and access your account. When you choose it, Google shares your name, email address, and profile picture with us. We use this only to create your account, sign you in, and contact you about your account.

Echo requests basic profile and email access only. It does not request access to Gmail, Google Calendar, Google Drive, or any other Google service, and cannot read, send, or modify data in those services. Echo’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

04How we use it

To run Echo for you: planning tasks, calling tools you authorised, returning output to your Slack workspace, and storing results against your account.

To operate the service: billing, security, fraud prevention, and improving reliability.

To communicate: account and product updates, security notices, and (where you opted in) launch and product email.

05Training and model use

We do not train any model on your messages, files, or tool data. We do not share your data with any model provider for training purposes.

Prompts are processed by model providers (today: Anthropic) via the OpenRouter inference gateway to generate responses. Their retention policies are described in their own terms and are listed on the Echo security page.

06Data and memory

To act like a capable employee, Echo builds a private memory for each workspace. This can include facts about how your business works, preferences about how you like Echo to work, a graph of the people, organisations, and projects you mention, a searchable index of past conversations, and any documents you add to Echo’s knowledge base.

Memory is isolated to your workspace. It is never shared with, or readable by, another customer or workspace, and it is used only to do your work, not to train models and not for advertising.

Some memory is written automatically as Echo works. Once a day, an optional review (called “Self-Improve”) reads a summary of the previous twenty-four hours of activity in your workspace and updates Echo’s facts, preferences, and knowledge graph. A workspace administrator can turn this review off at any time in the dashboard.

Sensitive memory is never saved silently. Before Echo stores a named or financial fact, or creates a new automated skill, it asks a workspace administrator to approve it first.

To provide search and memory, text is converted into numerical representations (embeddings), and any audio or voice notes you send are transcribed to text. These steps are carried out by the processing subprocessors listed on the Echo security page, and the content is not used to train those providers’ models.

You stay in control. Workspace administrators can view and delete memories, facts, and connections in the dashboard, disable automatic learning, and reject anything Echo proposes to remember. To limit what we hold, Echo automatically prunes its searchable index of older conversations after ninety days.

07Sharing

We share data only with the subprocessors listed on the security page, and only as needed to run Echo.

We do not sell your data, and we do not share it with advertisers.

08Storage and security

Data is stored in Supabase Postgres and Supabase Storage, hosted in the United States (AWS, us-east-1), encrypted at rest with AES-256.

Traffic between Echo and your tools is encrypted with TLS 1.2 or higher.

09Retention and deletion

Threads, files, and tool credentials are retained for the life of the workspace. You can delete any of them from the dashboard at any time.

When you delete a workspace, content is removed from active systems within thirty days and from backups within ninety days.

10Your rights

You can access, export, correct, or delete your data at any time. Most actions are available in the dashboard. For anything that is not, write to [email protected].

If you are in the UK or EU, you also have the right to lodge a complaint with your data protection authority.

11Cookies

The marketing site uses strictly necessary cookies only. The dashboard uses cookies to keep you signed in.

We do not use third-party advertising cookies. For the full detail, see the cookie policy at /legal/cookies.

12Changes to this policy

When we change this policy in a material way, we notify workspace owners by email at least thirty days before the change takes effect.

The effective date at the top of this page reflects the latest version.