Effective date: 2026-08-03
EchoLing is designed with privacy in mind. AI-generated recall cards pass through EchoLing's backend and the relevant processing provider. We do not sell your personal information or use your saved vocabulary for third-party advertising.
Account and session identifiers. Before you register, EchoLing creates a pseudonymous guest account so Starter content, learning progress, sync, and Widget exposure can work across our app and backend. We store its authentication user ID and an internal app user ID, but it is not a recoverable login and does not contain an email address. If you later register, we link or merge that guest data into your registered account.
Device and request metadata. Our servers log platform, app version, operating system, device model, IP address, timestamps, and request logs for security and debugging purposes. For guest usage limits, the app creates a random installation identifier in the device Keychain. We do not use an Apple hardware identifier and do not store the raw installation identifier or raw IP in the guest allowance record; the server stores keyed, pseudonymous hashes instead.
Content you submit. When you use AI generation, the text you submit is processed by our backend and the relevant provider. Saved vocabulary entries are stored in our database linked to your account.
Usage and quota data. We track daily AI generation quota consumption, generation job records, and idempotency keys to prevent abuse and deliver consistent service. Creating or accepting an entry is not itself quota-limited; quota is consumed only when eligible AI content is generated.
Product interactions, preferences, and feedback. We store account-linked events such as cards shown, review responses, recommendation actions, and sync mutations. We also store account preferences you provide during onboarding, including how you heard about EchoLing. If you submit product feedback, we store its message, category, optional contact information, submission status, and basic app/device metadata. We use this information to operate learning features, prevent duplicate processing, diagnose problems, and improve the product.
Local data on your device. Entries, memory packs, and pending sync operations are stored in a local database on your device. Your current learning exposure position and recall language preference are also stored locally.
We use your data solely to provide and improve EchoLing:
We do not use your saved vocabulary or submitted text to train AI models for third parties, nor do we use it for targeted advertising.
Supabase — authentication and database. Your account data and saved entries are stored in Supabase-managed infrastructure. See supabase.com/privacy.
AI recall card generation provider — Text you submit for AI recall card generation is sent to our current AI provider for processing. Their data retention policies apply; please review the provider's privacy terms for details on how submitted text is handled. We will update this policy if we change providers.
Vercel — hosting and request logs. Standard server-side logs including IP addresses are retained per Vercel's applicable retention settings.
Apple — App Store distribution and push notification delivery. Apple's privacy policy governs these interactions.
Unregistered guest accounts and their associated content are automatically deleted after 30 days without activity. Guest source records that have been merged into a registered account are deleted after a short operational recovery period. The pseudonymous installation allowance record and its cumulative guest-entry count are retained to enforce the lifetime three-entry guest limit; it contains neither the raw installation identifier nor a raw IP address. Registered account data, saved vocabulary entries, product interactions, and submitted feedback are retained until you delete them or delete your account, except where a longer period is required for security or legal obligations. You can delete your account directly in the app from the Me page — this deletes account-linked entries, memory cards, quota records, sync history, interactions, feedback, and authentication mappings from our application database. It also clears associated local data from your device.
Server-side request logs follow the default retention policy of our hosting platform (Vercel). AI provider data retention follows each provider's applicable terms — we recommend reviewing our current AI provider's privacy terms for details on how submitted text is handled.
You may delete your account and associated application data directly within the app at any time via the Me page.
For other requests — including data access, export, or correction — contact us at hello@echoling.app. We will respond within 30 days.
California residents may have additional rights under the California Consumer Privacy Act (CCPA/CPRA), including the right to know, delete, and opt out of sale of personal information. As noted above, we do not sell personal information. For questions, contact us at the email above.
EchoLing is not directed at children under 13 years of age. We do not knowingly collect personal information from children under 13. If you believe we have inadvertently collected such information, please contact us immediately at hello@echoling.app.
All data in transit is encrypted using TLS. Backend API keys and service credentials are server-side only and are never distributed to client apps. We apply the principle of least privilege to database and service permissions and minimize logging of user content.
We may update this policy as EchoLing evolves. When we make material changes, we will update the effective date at the top of this page and, where appropriate, notify you through the app. Continued use of EchoLing after changes constitutes acceptance of the updated policy.
For privacy questions, data requests, or to report a concern, contact us at hello@echoling.app.
Contact: hello@echoling.app