Privacy Policy
Last updated: January 2026
1. Introduction
EchoReply ("we", "us", or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our Chrome extension and related services.
By using EchoReply, you agree to the collection and use of information in accordance with this policy.
2. Information We Collect
2.1 Information You Provide
We collect information that you voluntarily provide when configuring your persona, including:
- Professional identity and role
- Current projects and status
- Communication tone preferences
- Vocabulary and writing style preferences
2.2 API Keys
If you choose to use OpenAI (GPT) or Google Gemini, you may provide API keys. These keys are:
- Stored locally in your browser using Chrome's storage API
- Never transmitted to our servers
- Only used to make requests to the respective AI service providers
- Under your complete control and can be deleted at any time
2.3 Usage Data
We may collect limited usage data to improve the Extension, including:
- Feature usage statistics (anonymized)
- Error logs and crash reports
- Extension version information
2.4 Subscription Information
If you subscribe to a paid plan, we collect:
- Payment information (processed by third-party payment processors)
- Billing address and contact information
- Subscription status and renewal dates
3. How We Use Your Information
We use the collected information for the following purposes:
- Service Provision: To provide and maintain the Extension's functionality
- Persona Configuration: To generate AI responses that match your configured persona
- Service Improvement: To analyze usage patterns and improve the Extension
- Customer Support: To respond to your inquiries and provide technical support
- Billing: To process payments and manage subscriptions
- Legal Compliance: To comply with applicable laws and regulations
4. Data Storage and Security
4.1 Local Storage
Your persona configuration and API keys are stored locally in your browser using Chrome's local storage API. This means:
- Data remains on your device
- Data is not synchronized to our servers
- You can clear this data at any time through Chrome's settings
4.2 Server Storage
We do not store the following on our servers:
- Your API keys
- Your persona configuration details
- Social media posts or conversations
- AI-generated response suggestions
4.3 Security Measures
We implement appropriate technical and organizational measures to protect your information, including:
- Encryption of data in transit
- Secure authentication and authorization
- Regular security assessments
- Access controls and monitoring
5. Third-Party Services
5.1 AI Service Providers
When you use EchoReply with OpenAI or Google Gemini:
- Your API keys are used to make requests directly to these providers
- Post content and context may be sent to these AI services to generate responses
- These providers have their own privacy policies governing data handling
- We recommend reviewing their privacy policies: OpenAI Privacy Policy and Google Privacy Policy
5.2 Payment Processors
For subscription payments, we use third-party payment processors. These processors handle payment information according to their own privacy policies and security standards.
5.3 Analytics
We may use analytics services to understand how the Extension is used. These services collect anonymized usage data and do not identify individual users.
6. Data Sharing and Disclosure
We do not sell, trade, or rent your personal information to third parties. We may share information only in the following circumstances:
- Service Providers: With trusted service providers who assist in operating the Extension (under strict confidentiality agreements)
- Legal Requirements: When required by law or to protect our rights and safety
- Business Transfers: In connection with a merger, acquisition, or sale of assets (with notice to users)
- With Your Consent: When you explicitly authorize us to share information
7. Your Rights and Choices
You have the following rights regarding your information:
- Access: Request access to personal information we hold about you
- Correction: Update or correct your persona configuration at any time
- Deletion: Delete your persona configuration and API keys through Chrome settings
- Subscription Management: Cancel your subscription at any time
- Data Portability: Request a copy of your data in a portable format
To exercise these rights, please contact us at support@echoreply.io
8. Children's Privacy
EchoReply is not intended for users under the age of 13. We do not knowingly collect personal information from children under 13. If you believe we have collected information from a child under 13, please contact us immediately.
9. International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence. These countries may have data protection laws that differ from those in your country. By using EchoReply, you consent to the transfer of your information to these countries.
10. Data Retention
We retain your information for as long as necessary to provide the Extension and fulfill the purposes outlined in this policy. Specifically:
- Persona configuration: Retained locally in your browser until you delete it
- Subscription information: Retained for the duration of your subscription and as required by law
- Usage data: Retained in anonymized form for service improvement
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by:
- Posting the new Privacy Policy on this page
- Updating the "Last updated" date
- Sending an email notification for significant changes
You are advised to review this Privacy Policy periodically for any changes.
12. California Privacy Rights
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA), including:
- The right to know what personal information is collected
- The right to delete personal information
- The right to opt-out of the sale of personal information (we do not sell personal information)
- The right to non-discrimination for exercising your privacy rights
13. GDPR Rights (European Users)
If you are located in the European Economic Area (EEA), you have additional rights under the General Data Protection Regulation (GDPR), including:
- Right of access to your personal data
- Right to rectification of inaccurate data
- Right to erasure ("right to be forgotten")
- Right to restrict processing
- Right to data portability
- Right to object to processing
14. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at: