Legal

Privacy Policy

Last updated: September 6, 2026

The short version

Echo is built privacy-first. Text-to-speech runs entirely on your device. The books, documents, and articles you read with Echo are processed locally and are never uploaded to our servers unless you explicitly choose to share something to the community library. We do not sell your data, we do not build advertising profiles, and we collect as little as we possibly can.

What the Echo app processes on your device

When you import a document (PDF, EPUB, DOCX, RTF, TXT, Markdown, or HTML), paste a URL, or share text into Echo, that content is parsed and narrated by the on-device Kokoro voice engine. This happens locally:

  • Your documents and their contents stay on your phone.
  • Your reading history, bookmarks, playback positions, voice settings, and personal pronunciation dictionary are stored locally on your device.
  • Fetching a web article downloads that page directly from the site you requested — the URL and content do not pass through Echo servers.

What leaves your device (only if you choose)

  • Community library submissions. If you submit a book or audio to the community library, that content, the title and description you provide, and your public profile name are uploaded so other users can access them. Only submit content you have the right to share.
  • Account data. If you create an account (used for community features and Premium), we store your email address and basic account records with our authentication provider.
  • Purchases. Premium subscriptions are processed by Google Play. We never see your payment card details.

What this website collects

  • Waitlist emails. If you join the launch waitlist, we store the email address you submit (via Netlify Forms) and use it solely to tell you about Echo's launch and closed-beta availability. You can unsubscribe with one click, and we delete your address on request.
  • Hosting logs. Our hosting provider (Netlify) may keep standard, short-lived server logs (IP address, user agent) for security and operations. This site does not run third-party advertising or tracking scripts.

Alpha tester applications

If you apply for the free alpha we keep what you type on that form: which platforms you can test, whether you have a book ready and its format and rough length, anything you add about yourself, how you would like to be reached, and, if you asked to test on Android, the Google account we need to add to the closed test. It is stored with your Echo account and with the exact wording of what you agreed to, so neither of us has to rely on memory later. A salted hash of your network address is kept to stop one person filing dozens of applications; it is never stored as an address.

We use it to choose testers and to contact you about the alpha. It is never sold, shared, or used for marketing, and there is no mailing list. Delete your Echo account and your application and any free alpha access go with it.

Bug reports from Echo Studio

Echo Studio is in alpha. When you press Send report in the app, or use the report form on the Studio page, we receive: the app and Windows version, CPU and memory, the render settings (voice, speed, format, chapter count), the last error, and the app's own diagnostic log. Before anything is written to that log, the app removes your Windows user name, the book's file name and title, and any long quoted text. Your manuscript is never included. The app shows you the exact contents before you send, and the log can be left out. Your email is included only if you tick the box asking for a reply. The one exception is the optional “words it read wrong” field for narration reports, which sends only what you type there. If you tick the reply box while signed in, the report is linked to your account so we can answer there. The form on the Studio page sends what you type, the Windows version you pick, your browser's name and language, and your screen size.

Reports are stored in our database (Supabase, hosted in the United States). A one-line summary, including the sentence you typed, may be forwarded to a private Discord channel so we see it quickly, and the website form falls back to Netlify Forms if our database is unreachable. A salted hash of your network address is kept for up to two days to limit abuse; it is not stored with the report. Closed reports are deleted once they are 90 days old, and every report is deleted 180 days after submission. To have a report deleted sooner, contact us with the reference code the app or form gave you.

Children

Echo is not directed at children under 13, and we do not knowingly collect personal information from children. If you believe a child has provided us personal information, contact us and we will delete it.

Your rights

You may request access to, correction of, or deletion of any personal data we hold about you (waitlist email, account data, community submissions) at any time by emailing hello@echomana.com. Because narration data never leaves your device, deleting the app deletes your local reading data.

Changes to this policy

If we change this policy, we will update this page and the date above. Material changes that affect app users will also be announced in the app.

Contact

Questions about privacy? Email hello@echomana.com.