1. Scope
This Privacy Policy explains how the Echo Notes service (“we”, “us”) handles personal data when you use local-first notes, accounts, optional cloud sync, AI assistance, and cloud automations at app.echonotes.top. It forms part of the Terms of Service. Availability of specific features may differ by deployment.
2. Information we process
We process the following categories of data, depending on the features you use:
- Account data: email address, securely derived credential verification data, account identifiers, and sign-up/sign-in timestamps;
- User Content: note titles, Markdown content, folder structure, ordering, tags, update times, and attachments you store;
- Assistant data: prompts you send, selected note excerpts used as context, folder context, conversation history, and generated drafts;
- Automation data: task names, schedules, time zones, configured public sources, conditions, versions, runtime configuration, plus run, delivery, and audit records;
- Diagnostics: request times, IP addresses, device and browser type, error categories, version-conflict metadata, and security events needed to operate and protect the service;
- Billing data: membership status and order references; payments are processed by payment providers and we do not store full payment card details.
3. Local-first storage on your device
Echo Notes is local-first: to support offline editing, your current browser stores note content, pending sync operations, cursors, assistant history for that browser, read-only snapshots of automations, language preference, and the minimum session information required to keep you signed in.
This means clearing site data in your browser can remove locally stored content that has not yet synced. Signing out ends the session but does not by itself delete synced server copies or your account; account deletion is described in Section 9.
4. Cloud sync
When you are signed in and sync is available, notes, folders, versions, change times, and synchronization metadata are sent over encrypted connections (TLS) to our servers for persistence, conflict coordination, and recovery. The application distinguishes locally saved content from synced content so you always know where a copy lives.
5. AI processing
When you start an assistant conversation or request a summary, draft, classification, or automation draft, we send the prompt and only the content required to complete that request (such as selected text or folder context) to the model provider configured for the service. Providers process this data under agreements with us to generate your response.
We do not use your notes or assistant conversations to train foundation models. Approval before writing does not remove the need to process the request online: an internet round trip to the model provider is inherent to AI features. AI availability depends on gateway configuration, provider capacity, usage budgets, and rate limits.
6. Cloud automations
Where enabled, the server stores your automation configurations and executes them on schedule against public sources you configure, together with run, delivery, and audit events. We use these records to show you results, diagnose failures, and prevent abuse.
7. Cookies and similar technologies
The service uses browser storage (such as localStorage and IndexedDB) and strictly necessary cookies or session tokens to keep you signed in, remember language preferences, and restore application state. We do not use advertising trackers or sell behavioral data to third parties.
8. How we share data
We do not sell personal data. We share it only with:
- Service providers (processors): cloud hosting, AI model providers, email delivery, payment processing, and monitoring vendors that process data on our instructions under contract;
- Legal requirements: where disclosure is required by applicable law or valid legal process;
- Business transfers: as part of a merger or asset transfer, with notice under this policy.
9. Retention, export, and deletion
We retain User Content until you delete it or close your account. When you delete your account, we delete or anonymize your account data, notes, assistant history, and automation configurations within fifteen (15) business days, and purge remaining backup copies within thirty (30) days after that, unless a longer period is required by law.
Security and operation logs are kept no longer than twelve (12) months, except where law requires longer retention. You can export your notes through the product or request a copy by contacting us.
10. International data transfers
Data is stored in the People's Republic of China by default. If processing requires a transfer across borders, we will comply with applicable cross-border transfer requirements, including entering into the required standard contracts and applying supplementary safeguards. Where you access the service from outside China, your data may be processed in accordance with this policy and applicable local law.
11. Your rights
Subject to applicable law, you have the right to access and copy your data, correct inaccuracies, delete data, restrict or object to certain processing, withdraw consent, and deactivate your account. To exercise any right, contact support@echonotes.top; we respond within fifteen (15) business days after verifying your identity. You may also lodge a complaint with the competent supervisory authority.
12. Children
The service is not directed at children under 14 (or the minimum age required in your jurisdiction). Personal information of children under 14 is treated as sensitive and processed only with the consent of a parent or guardian where required. If you believe a child has provided personal information without proper consent, contact us and we will delete it promptly.
13. Security measures
We protect data with TLS encryption in transit, salted and hashed credential storage instead of plaintext passwords, role-based access control, audit logging for sensitive operations, and least-privilege access for service personnel. No system is perfectly secure; if a breach affects your rights, we will notify you and regulators as required by law.
14. Changes to this policy
We may update this policy to reflect product or legal changes. The current version is published here with its effective date, and material changes will be announced through the application or email in advance where reasonably possible.
15. Contact
For privacy questions or to exercise your rights, contact support@echonotes.top.
16. Related terms
Service scope, acceptable use, and AI output boundaries are covered in the Terms of Service.