Privacy Policy
How we protect your voice and your trust.
Version 3.1 · Last Updated: August 13, 2026 · Effective: August 13, 2026
Echoes (“Echoes,” “we,” “us,” or “our”) is a product of Agentic Software Solutions, LLC, a California limited liability company. This Privacy Policy describes how we collect, use, disclose, retain, and protect your personal information when you use the Echoes mobile application (the “App”), our website at echoesmemoirs.com (the “Website”), and all related services (collectively, the “Service”).
By accessing or using the Service, you acknowledge that you have read and understood this Privacy Policy.
Everyone who uses Echoes must be 18 or older — both account holders and storytellers. We do not knowingly collect personal information from anyone under 18.
Plain-language summaries labeled “The short version” appear throughout for readability. They are not a substitute for the full text, which governs. A separate Plain English Summary covers the basics of both this Policy and our Terms of Service.
1. INFORMATION WE COLLECT
The short version: We collect what you give us (your account, your recordings, your stories), what our AI helps create from it (transcripts, timelines, your memoir), and basic usage information. Your memoir photos never leave your device, and we never build a “voiceprint” or use your voice to identify you.
1.1 Information You Provide Directly
Account Information. When you create an account, we collect your email address, display name, and authentication credentials. If you sign in via Apple or Google, we receive your name and email address from those providers. You can create an Echoes account either in the App or on our Website — claiming a gift and buying Echoes for yourself on the Website both create the same kind of account, and it is the same account you then sign into on your phone.
Storyteller Profile Information. When you set up a storyteller profile, we collect the storyteller’s name, relationship to the account holder (e.g., “grandmother,” “father”), optional nickname, optional hometown, and optional birth year.
Voice Recordings and Audio Data. When you use our recording features, we capture audio recordings of interview sessions via your device’s microphone. These recordings contain the storyteller’s voice and all spoken content, including personal stories, family histories, names of individuals, places, dates, and life events. We also retain the AI interviewer’s side of the conversation as audio, so that both voices can be woven into your audio memoir.
Transcripts. We generate text transcripts of recorded sessions, including everything spoken by both the storyteller and the AI interviewer.
Demo Recording. Before purchase, you may try a short demo in which you answer one question. The demo recording stays on your device and is transcribed by Apple’s speech recognition — on-device where your device supports it (on some older devices or languages, Apple may process the audio on its servers under Apple’s terms). Your demo recording and words are never sent to us or to OpenAI; the demo’s only server request synthesizes a fixed, pre-written narration phrase.
Photos. If you add photos to your memoir book, those photos are stored only on your device. They are not uploaded to our servers or to any third party by the App.
Consent Preferences. We collect your explicit consent choices regarding voice recording, story content storage, third-party mentions, AI disclosure acknowledgment, the not-therapy disclaimer acknowledgment, and your data retention preference (indefinite, three years, or one year).
Topic Preferences. You may tell the App which topics you would rather not discuss. We store the descriptions and keywords you enter so the AI interviewer can steer away from them in every session. This is a preference you write yourself; we do not draw any health or psychological conclusion from it.
Family Information. If you use family sharing features, we collect family group names and each member’s name, email address, and role (storyteller, listener, or organizer). Family members may leave comments on shared stories, which we store.
Gift Purchase Information. Gifts are purchased on our Website through Stripe. We receive the purchaser’s name and email address, the gift message they write, and an optional prefilled storyteller name and relationship. We use the purchaser’s email only to deliver the gift code and confirmation. The gift recipient is not emailed by us — the purchaser shares the code directly. Card details are handled entirely by Stripe; we never receive or store card numbers.
1.2 Information We Generate or Derive
Structured Story Data. From your interviews we build a structured record of what was said, so later sessions can pick up where earlier ones left off. It has four parts:
- Entities and relationships — people, places, events, dates, and how they connect (e.g., “married to,” “worked at”), forming a “story graph.” This extraction runs on your device.
- A fact ledger of factual claims, including facts about other people the storyteller mentions, each tagged with its source (user-stated, user-confirmed, or AI-inferred), a confidence level, and any contradictions between sessions. Fact extraction is performed by OpenAI models via our backend.
- Timeline events — life events with their approximate dates, ages, and seasons.
- Narrative threads — open conversational threads and follow-up opportunities for future sessions.
Audio Stories and Memoir Content. We generate narrated audiobook compilations and written memoir content from your recorded interviews, including titles, subtitles, and section breakdowns. The audiobook narrator is a stock synthetic voice; the storyteller you hear in your audiobook is their actual recording, not a synthetic recreation.
No Voiceprints or Biometric Identifiers. We do not create voiceprints, do not analyze voice recordings to identify who is speaking, and do not clone, model, or synthetically recreate anyone’s voice. Voice recordings are used only as content — to transcribe, and to include the storyteller’s real voice in their memoir.
Usage Data. We track recording session duration, chapter progress, and cumulative usage time to operate the Service, maintain service integrity, and monitor our costs.
1.3 Information Collected Automatically
Device and Technical Information. We may collect device type, operating system version, app version, and app-instance identifiers through the Firebase SDK.
App Analytics Events. We log product usage events such as session starts and completions, chapter completions, paywall views, and purchase completions, processed by Firebase Analytics. Analytics events contain counts, durations, and product identifiers — never your recordings, transcripts, or story content. App analytics collection is on by default; you can turn it off at any time in the App’s Settings.
Website Analytics. Our Website is hosted by Netlify, and we use Netlify’s built-in analytics to understand traffic. It works from our web server’s own request logs — there is no analytics script on the Website, and no analytics cookie or analytics identifier is assigned to you. It reports aggregate measurements only: how many pages were served, an approximate visitor count, the pages viewed, referring sites, approximate location, and requests for pages that do not exist. Netlify retains this for a rolling 30-day window. We set no advertising or cross-site tracking cookies anywhere on the Website, which is why you will not see a cookie banner.
Signing In on the Website. Most of the Website is exactly as described above: you can read every page without giving us anything or being identified. Four pages are different, because they are where you create an Echoes account — claiming a gift, buying Echoes for yourself, and the pages that follow each. This is a change from Version 3.0 of this Policy, when accounts could only be created in the App.
On those pages we use Firebase Authentication, which runs in your browser and stores your sign-in session in your browser’s local storage so that you are not signed out part-way through creating your account. While it is stored, that session is a persistent identifier for you. It is strictly necessary to create and use an account, and it is never used for analytics, advertising, or tracking you across other websites. Signing out, or clearing your browser’s site data, removes it.
Where you use the Website to create an account, we collect what Section 1.1 describes under Account Information, plus the storyteller’s name if the gift did not already carry it, and a record that you accepted our Terms of Service and this Privacy Policy — including which version, and when.
No Advertising Tracking. The Service contains no advertising SDKs, does not access the advertising identifier (IDFA), does not use App Tracking Transparency because it does not track, and does not track you across other companies’ apps or websites.
Crash and Performance Data. We may collect crash logs and performance metrics through Firebase to maintain and improve the Service.
1.4 Information from Third Parties
Authentication Providers. If you sign in using Apple Sign-In or Google Sign-In, we receive your name and email from those providers pursuant to their own privacy policies.
RevenueCat (In-App Purchases). We use RevenueCat to manage in-app purchases. RevenueCat receives your app user ID and processes purchase receipts, providing us with purchase entitlements, product identifiers, and transaction status. We do not receive or store your payment card information.
Stripe (Website Gift Purchases). Stripe processes gift payments on our Website and provides us with the purchaser’s email address and transaction status. Card data goes to Stripe, never to us.
2. HOW WE USE YOUR INFORMATION
The short version: We use your information to run the Service — the interviews, the transcripts, the memoir, family sharing, and gifts. We don’t sell it, we don’t use it for advertising, and we don’t train AI models on it.
To Provide and Operate the Service. Facilitating AI-assisted voice interviews, generating transcripts, extracting entities and timeline events, creating audio stories and memoir books, and managing family sharing.
To Process Your Recordings Through AI. During live interviews, the storyteller’s voice audio streams to OpenAI so the AI interviewer can hear and respond. Transcripts, extracted entities, timeline events, topic preferences, and story graph data are included in AI prompts so questions stay relevant across sessions. See Section 12.1.
To Fulfill Gift Purchases. Creating the gift code, showing it to the purchaser, and emailing it (via Resend, our email delivery provider).
To Show Crisis Resources When Needed. The App watches for signs of distress during a session and can display crisis resources. This runs entirely on your device — see Section 12.2.
To Process Payments and Manage Entitlements. We use RevenueCat (in-app) and Stripe (Website gifts) to verify purchases and manage access, including pausing access if a purchase is refunded or disputed.
To Maintain Service Integrity, Improve the Service, and Communicate with You. We track usage and apply rate limits to keep the Service reliable; we use aggregated, de-identified analytics to diagnose issues and improve features; and we send transactional messages such as password resets and gift delivery emails.
To Comply with Legal Obligations. We may process your information as required by applicable law or in response to valid legal process.
3. HOW WE SHARE YOUR INFORMATION
The short version: Your data goes only to the service providers that make Echoes work, and to the family members you choose to share stories with. We never sell it.
We do not sell your personal information. We do not use your voice recordings, transcripts, or story content for advertising, and we do not use them to train AI models. We share your information only in the following limited circumstances:
3.1 Third-Party Service Providers
| Provider | Purpose | Data Shared |
|---|---|---|
| OpenAI | AI-powered voice interviews, transcription, text-to-speech, story analysis | During live interviews, voice audio streams directly from your device to OpenAI over an encrypted connection. Text-based processing (fact extraction, memoir generation, narration synthesis) is routed through our backend. AI prompts include storyteller context: name, relationship, extracted entities, timeline events, topic preferences, and prior-session summaries. |
| Firebase (Google Cloud) | Authentication (in the App and on the Website), cloud database, file storage, analytics | Email, display name, and synced account data (stories, profiles, timeline events, entities, facts, consent records). Your own audio and transcripts are uploaded as client-side-encrypted content (see Section 4.1); copies of stories you share with family are stored without that added encryption layer so family members can play them. When you create an account on the Website, your browser authenticates with Firebase directly and stores a sign-in session locally (see Section 1.3). |
| RevenueCat | In-app purchase management | App user ID, purchase entitlements, product identifiers, transaction data |
| Stripe | Website payment processing — both gifts and purchases for your own account | Your payment details (to Stripe directly), name, email, and, for a gift, the gift personalization; we receive email and transaction status, never card numbers |
| Resend | Gift email delivery | The purchaser’s email address, purchaser name, gift message, and gift code. If the purchaser gives us the recipient’s email address, we also email the recipient at that address, carrying the gift message and the link used to claim it. |
| Apple | Authentication (if Apple Sign-In used); speech recognition for the demo | Name, email (per Apple’s privacy controls); demo audio may be processed by Apple for transcription on devices without on-device recognition |
| Authentication (if Google Sign-In used) | Name, email, OAuth token | |
| Netlify (Netlify, Inc.) | Website hosting and server-side analytics | Standard web-server request data (the page requested, referring site, approximate location, browser type), which Netlify aggregates into traffic statistics. No analytics script, no cookies, no persistent identifier. Retained for a rolling 30 days. |
3.2 Family Members You Authorize
If you mark a story as shared with your family group, members of that group can: listen to the full recording (via a separate copy stored without client-side encryption so it can be played — see Section 4.1), see the story’s title, storyteller name, topic tags, and a short transcript preview (the opening exchanges of the session), and leave comments visible to the group. Every family member has their own account and role (storyteller, listener, or organizer). You can unshare a story at any time in the App.
3.3 Legal Requirements
We may disclose your information if required to do so by law, regulation, subpoena, court order, or other governmental request, or when we believe in good faith that disclosure is necessary to protect our rights, your safety, or the safety of others.
3.4 Business Transfers
In the event of a merger, acquisition, reorganization, bankruptcy, or sale of all or substantially all of our assets, your personal information may be transferred as part of that transaction. We will notify you via email or prominent notice on the Service before your information becomes subject to a different privacy policy.
3.5 With Your Consent
We may share your information for other purposes with your explicit consent.
4. DATA STORAGE AND SECURITY
The short version: Your own recordings and transcripts are encrypted on your device with a key that lives in your iCloud Keychain — our servers never hold it. Copies you share with family are protected by access controls and standard cloud encryption instead, so your family can actually play them. During a live interview, your voice goes straight to OpenAI over an encrypted connection.
4.1 Where Your Data Is Stored
On Your Device. Story data, transcripts, profiles, timeline events, entities, and other content are stored locally. Memoir photos are stored only on your device and never uploaded.
Your Encrypted Copies. Your audio recordings and transcripts are encrypted on your device using AES-256-GCM before being stored or uploaded. The key is generated on your device and stored in your iCloud Keychain — it syncs across your own Apple devices and is never held by, or derivable by, our servers. In rare situations where the key is temporarily unavailable, content may be saved without this added layer until it can be re-secured; it remains protected in transit and by cloud-provider encryption at rest.
In the Cloud. Your data syncs to Google Cloud Firestore and Firebase Storage, hosted in the United States. All data at rest is additionally encrypted by Google. Access is restricted by security rules to your authenticated account (and, for shared stories, to your family group’s members).
Family-Shared Copies. When you share a story with your family, a separate playable copy of the recording (and a short transcript preview) is stored for the family group without the client-side encryption layer described above — this is what allows family members to listen. These copies are protected by family-membership access rules and Google’s encryption at rest.
At OpenAI. During active recording sessions, voice audio streams directly from your device to OpenAI’s servers over encrypted WebSocket connections using short-lived session credentials issued by our backend. Section 12.1 describes OpenAI’s data handling.
4.2 Security Measures
We implement commercially reasonable technical and organizational measures to protect your personal information, including encrypted transmission for all connections (HTTPS/TLS and encrypted WebSockets), client-side AES-256-GCM encryption of your audio and transcripts as described above, Firebase security rules restricting access to authenticated owners and authorized family members with a default-deny posture, rate limiting on backend endpoints, and storage of the OpenAI API key exclusively on our backend servers.
4.3 No Guarantee; Breach Notification
No method of transmission over the internet or electronic storage is 100% secure, and we cannot guarantee absolute security of your personal information. If a breach affecting your personal information occurs, we will notify you and the relevant authorities as required by applicable law.
5. DATA RETENTION
The short version: You choose how long your original recordings are kept — forever, three years, or one year — and a nightly automated job enforces your choice. Deleting your account erases your cloud data. One honest caveat: details of stories you shared with family (the title, a short preview, and comments) can remain visible to that family group even after you delete your account.
Default Retention. We retain your personal information for as long as your account is active or as needed to provide the Service, unless you select a shorter retention period.
Retention Preferences — Automatically Enforced. During onboarding you choose a data retention preference: indefinite, three years, or one year. A nightly automated job enforces this choice: stories older than your selected window — including their recordings and their transcripts — are deleted from our cloud systems, and the App removes the corresponding local copies. Memoir content you have already generated (your compiled memoir book text and audio stories) is not affected by this sweep. You can change your retention preference at any time in the App’s Settings.
In-App Deletion Controls. At any time, in Settings, you can delete your voice recordings only (keeping transcripts and memoir text), clear extracted story details (the fact ledger and story graph), or delete everything. Deletions also remove the corresponding copies stored in the cloud.
Account Deletion. You may delete your account at any time in the App’s Settings. Account deletion triggers a server-side erasure of your cloud data — your audio files (including the playable copies of stories you shared with family), stories, chapters, transcripts, timeline events, fact ledger, topic preferences, consent records, story graph, profiles, and usage records — followed by deletion of your authentication credentials. Deletion is permanent and cannot be undone. What may persist: the descriptive details of stories you shared with a family group (title, storyteller name, a short transcript preview) and comments you left in family groups may remain visible to that family group after your account is deleted. Deleting your account does not by itself initiate a refund.
Aggregated Data. We may retain aggregated, de-identified data that cannot reasonably be used to identify you for as long as commercially useful.
Website Traffic Statistics. Netlify’s server-side analytics for our Website are retained on a rolling 30-day window and are not linked to you (see Section 1.3).
6. YOUR RIGHTS AND CHOICES
The short version: You can see, correct, download, or delete your data — much of it directly in the App — and every U.S. user gets the same rights, not just Californians. Email echoes-legal@agenticsoftwaresolutions.io and we’ll respond within 45 days.
6.1 Controls in the App
You do not need to contact us to exercise most of your choices:
- Export your transcripts, audio, and memoir (PDF and ePub) from the App at any time.
- Delete your voice recordings only, your extracted story details, or everything — in Settings.
- Delete your account, which erases your cloud data as described in Section 5.
- Change your retention preference at any time in Settings.
- Turn off App analytics at any time in Settings.
- Withdraw recording consent by ceasing use of the recording features. Previously recorded data is retained according to your retention preference unless you delete it.
- Revoke microphone access in your device’s iOS Settings. Recording features will not function without it.
6.2 Your Rights — All U.S. Residents
We extend the following rights to every user in the United States, regardless of which state you live in:
- Right to know and access. Request the categories and specific pieces of personal information we hold about you, the sources, the purposes, and the categories of third parties we shared it with.
- Right to correct inaccurate personal information.
- Right to delete your personal information, subject to narrow exceptions such as legal compliance obligations.
- Right to portability — receive your data in a portable format, or export it yourself in the App.
- Right to non-discrimination. We will not treat you differently for exercising these rights.
No sale, no targeted advertising, no profiling. We do not sell personal information, do not share it for cross-context behavioral advertising or targeted advertising, and do not conduct profiling in furtherance of decisions producing legal or similarly significant effects. There is nothing to opt out of.
Sensitive information. We collect information that qualifies as sensitive: your account login credentials, your voice recordings and the contents of your stories, and — inherently, because they are life stories — details your storyteller may mention about health, religion, or family. We use this information only as necessary to provide the Service described in this Policy, and never to infer characteristics for other purposes. You may ask us to limit its use to that purpose.
Categories of personal information collected in the preceding 12 months: identifiers (name, email, user ID); audio and visual information (voice recordings); internet or network activity (app analytics events, device information); commercial information (purchase and gift records); inferences drawn from the above (extracted entities, timeline events, fact ledger, narrative threads); and sensitive personal information (account credentials, voice recordings and story contents).
How to exercise your rights. Email echoes-legal@agenticsoftwaresolutions.io. We will verify your identity before acting on a request, and you may designate an authorized agent. We respond within 45 days, extendable once by a further 45 days where reasonably necessary, with notice. If we decline your request, you may appeal by replying to our decision; we will respond to the appeal within 45 days. If your appeal is unsuccessful, you may contact your state Attorney General.
6.3 Health-Related Information
Some of what a storyteller says in a memoir interview will naturally touch on health — an illness, a surgery, the loss of a spouse. That information lives in your recordings and transcripts, and we treat it with the same protections as the rest of your story content.
We do not analyze your sessions to label emotional state, and we do not keep records of crisis detections. Crisis detection runs on your device and leaves no stored log (Section 12.2). We do not sell health-related information, do not share it for advertising, and do not use it for marketing. You can delete it using the controls in Section 6.1. Questions or requests: echoes-legal@agenticsoftwaresolutions.io.
7. INTERNATIONAL DATA TRANSFERS
The Service is operated from the United States and is directed to U.S. residents. If you access the Service from outside the United States, your information will be transferred to, stored in, and processed in the United States, where data protection laws may differ from those in your jurisdiction.
8. AGE REQUIREMENT
Everyone who uses Echoes must be 18 or older — both the account holder and the storyteller being interviewed. We do not knowingly collect personal information from anyone under 18. If you believe we have collected information from a minor, contact echoes-legal@agenticsoftwaresolutions.io and we will delete it promptly.
9. THIRD-PARTY LINKS AND SERVICES
The Service may contain links to third-party websites or services (for example, crisis hotlines). We are not responsible for their privacy practices and encourage you to review their policies.
10. CHANGES TO THIS PRIVACY POLICY
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on the Website and within the App, updating the “Last Updated” date, and, where required by law, providing additional notice such as email. Your continued use of the Service after the effective date constitutes acceptance of the revised Policy.
11. DO NOT TRACK AND GLOBAL PRIVACY CONTROL
We do not sell personal information or share it for cross-context behavioral advertising, and our Website sets no analytics or advertising cookies. Because there is no tracking to disable, “Do Not Track” and Global Privacy Control signals have no data for us to act on.
12. ADDITIONAL DISCLOSURES
12.1 OpenAI Data Processing
When you use the recording features, the storyteller’s voice audio is transmitted in real time directly from your device to OpenAI via an encrypted WebSocket connection, using short-lived session credentials issued by our backend. Text-based AI processing (fact extraction, memoir and narration generation) is routed through our backend, and our OpenAI API key is never exposed to your device. Contextual information about the storyteller — name, relationship, previously extracted entities and relationships, timeline events and gaps, narrative threads, topic preferences, and prior session summaries — is included in AI prompts to make interviews coherent across sessions. This means something mentioned in an early session may be referenced and built upon much later. To keep specific information out of future sessions, set a topic preference in the App, clear your extracted story details in Settings, or contact us.
Under OpenAI’s API policies, data submitted through the API is not used to train OpenAI’s models and is retained by OpenAI for a limited period for abuse monitoring. We have requested zero-data-retention handling from OpenAI and will update this Policy when it is confirmed. For current information, see OpenAI’s API data usage policies at https://openai.com/policies.
12.2 Crisis Detection and Resources
The App watches interview sessions for signs of emotional distress using automated keyword matching that runs entirely on your device. This detection is best-effort: it may miss a genuine crisis and may occasionally trigger when no crisis exists. When triggered at the highest severity, the App pauses the recording and displays crisis resources, including the 988 Suicide & Crisis Lifeline, the Crisis Text Line (text HOME to 741741), and Adult Protective Services (1-800-677-1116). These resources are U.S.-specific.
The Service never contacts emergency services, hotlines, or any other person or organization on your behalf — any call or text to a resource is initiated by you. We do not create or store a record of these detections. Nothing about a crisis detection is logged, synced to our servers, or retained after the session.
13. CONTACT US
Agentic Software Solutions, LLC Privacy and legal requests: echoes-legal@agenticsoftwaresolutions.io General support: echoes-support@agenticsoftwaresolutions.io
DOCUMENT HISTORY
- v3.0 — August 2, 2026. Scope reduction. Sentiment and emotional-tone analysis discontinued and its disclosures removed; crisis detection remains on-device and no longer creates a stored record. Storytellers must now be 18 or older, replacing the prior minor-storyteller framework. Website analytics moved to a cookieless service, removing the cookie banner, cookie table, and consent-mode disclosures. California and other-state privacy rights merged into a single section extending the same rights to all U.S. residents. Consumer health data section rewritten to reflect the reduced data footprint.
- v2.1 — July 23, 2026. Added disclosures for consent-gated Google Analytics 4 on the Website (superseded by v3.0).
- v2.0 — July 23, 2026. Comprehensive update following the July 2026 launch: single-purchase model; website gift purchases via Stripe and gift email delivery via Resend; automated retention enforcement and in-app deletion controls now live; accurate description of client-side encryption scope and family-shared copies; added demo recording and photos disclosures; added no-voiceprint statement; added multi-state privacy rights and consumer health data sections; updated OpenAI processing description.
- v1.0 — March 29, 2026. Initial publication.
This Privacy Policy is provided for informational purposes and does not constitute legal advice. We recommend consulting with a qualified attorney for legal guidance specific to your situation.