Privacy Policy
Your recordings are yours.
This policy explains what Echoryte collects when you transcribe, translate, edit, and export recordings, why we hold it, who processes it on our behalf, how long it stays, and how to get it back or delete it.
Privacy Policy
Last updated 29 August 2026. Questions about this policy, or any request to access, export, or delete your data, go to support@echoryte.com.
Who we are and how to reach us
Echoryte provides the transcription, subtitle, translation, and AI review service described on this site. For the personal data you submit through the service, Echoryte is the controller; for the content inside your recordings, you remain responsible for having a lawful basis to upload it, and we process that content on your instructions.
Reach us about anything in this policy at support@echoryte.com. If you are in a jurisdiction that gives you a right to complain to a supervisory authority, you can do that at any time without contacting us first.
What we collect
Account data: your email address, name if you provide one, password hash, interface language, email verification and session state.
Content you upload: audio and video files, and everything the service derives from them — playback media, waveforms, transcripts, your edits, speaker labels, translations, AI notes and chat, and generated exports.
Usage and operational data: job status, processing duration, error and retry records, quota consumption, file and folder metadata, and the security logs (IP address, user agent, timestamps) we need to authenticate sessions and stop abuse.
Billing data: your Stripe customer and subscription identifiers, plan, billing interval, and payment status. Card numbers are entered directly into Stripe and are never sent to or stored by Echoryte.
Why we process it
We use account and content data to run the service you asked for: transcribing, translating, editing, exporting, and keeping your files available in your workspace.
We use usage and operational data to keep the service working — enforcing plan limits, diagnosing failed jobs, measuring capacity, and protecting accounts against abuse and fraud.
We use billing data to take payment, apply your plan entitlements, and meet tax and accounting obligations.
We use your email address for transactional messages: verification, password reset, security notices, billing events, and job results. Product or marketing email is separate and only sent if you opt in; you can withdraw that at any time from the link in the message.
Where the GDPR or a similar law applies, our legal bases are performance of a contract (running the service and billing you), legitimate interests (security, abuse prevention, service improvement, and privacy-filtered service analytics), consent (optional email), and legal obligation (tax and accounting records).
Who else processes your data
We do not sell personal data, and we do not use the content of your recordings, transcripts, or AI outputs to train our own or any third party’s models.
The providers currently used to run Echoryte are Vercel (web hosting), Neon (database), Cloudflare R2 (media and export storage), Railway and Redis (background jobs), Deepgram and AssemblyAI (speech recognition), Google AI services (translation and AI features), Google Analytics (traffic and conversion measurement), Resend (transactional email), and Stripe (payments). Plausible or PostHog may also be enabled for privacy-filtered marketing or product analytics.
A provider receives only the data needed for its function. These services operate internationally, so data may be processed outside your country under the provider’s published privacy and transfer terms. Contact us if you need the current processor details before uploading sensitive material.
We may also disclose data where we are legally required to, or where it is necessary to establish, exercise, or defend legal claims. If Echoryte is ever involved in a merger or acquisition, data may transfer to the successor under this policy.
How long we keep it
Anonymous trial files and their metadata are deleted automatically 24 hours after upload if they are not claimed into an account.
Files you delete go to the trash for 30 days, where you can restore them. After that window a background job permanently removes the stored objects, the provider-side jobs where the provider supports deletion, and the database records.
Export artifacts have a short download expiry and are cleaned up automatically after it passes.
If you delete your account, we remove your files and account records within 30 days, except where we must keep something longer — billing and tax records for the statutory retention period, and security logs for a short window where they are needed to investigate abuse.
Your rights and controls
You can access and correct your account details, export your data in a portable form, and delete individual files or your whole account from within the app at any time.
Depending on where you live, you may also have the right to object to or restrict processing, to withdraw consent, and to complain to a supervisory authority. California residents have the rights to know, delete, correct, and opt out of sale or sharing — we do not sell or share personal information as those terms are defined.
To exercise any right that is not available in the app, write to support@echoryte.com from the address on the account. We answer within 30 days and may ask you to confirm you control the account before acting on a request.
Cookies and local storage
We use secure, HttpOnly cookies for sign-in sessions and anonymous trial access. These are strictly necessary and cannot be turned off while you use the service.
Your browser also stores editor and upload state locally so that an interrupted edit or upload can be recovered. That data stays on your device and is cleared when you sign out or clear site data.
Analytics scripts load when you visit the site, except on local tool routes that explicitly run without third-party analytics. Analytics receives a filtered page path and allowlisted event properties; it does not receive file names, recording or transcript content, prompts, account identifiers, or sensitive query parameters through our event instrumentation. You can block or clear analytics cookies with your browser settings.
Security and children
Media and exports are encrypted in transit and at rest. Access to production systems is limited to the people who need it, authentication uses hashed credentials and short-lived sessions, and uploads move directly to object storage over signed, expiring URLs.
No system is perfectly secure. If a breach affects your personal data and applicable law requires it, we will notify you and the relevant authority without undue delay.
Echoryte is not directed at children under 16, and we do not knowingly create accounts for them. If you believe a child has given us personal data, write to us and we will delete it.
Changes to this policy
We may update this policy as the service changes or the law does. The date at the top always reflects the current version.
If a change materially affects how we use your data, we will tell you by email or in the app before it takes effect. Continuing to use Echoryte after that date means the updated policy applies. If you disagree with it, you can export your data and close your account, or write to support@echoryte.com.