Your Echo
Privacy Policy
Last updated 21 July 2026
Your Echo is a private health and wellness app built around a relationship with your own future self. To provide that experience it handles some of your most personal information — including health data, conversations, photos, and a sample of your voice. This policy explains what we collect, why, who processes it on our behalf, and the control you have over it.
What we collect
- Account and profile: your name, email address, sex at birth, date of birth/age, height and weight, and the priorities or goals you choose to share.
- Photos: a few photos you choose, used to generate your stylized future-self portrait and home image.
- Voice sample: a short recording you provide, used to create a similar (not identical) cloned voice for your calls.
- Health & activity data: with your permission, data from Apple Health and wearable accounts you choose to connect. Depending on the source and permissions you approve, this can include workouts, heart rate, HRV, resting heart rate, recovery and strain scores, sleep, steps, active energy, body measurements, and workout routes or precise location when a recorded workout includes them.
- Conversations and Investigations: messages, voice notes, call audio and transcripts, questions, responses, cited sources, and structured facts or findings derived from the context you provide.
- Sensitive context you choose to provide: for high-trust features, information such as medication or reproductive-health context. These features require an explicit choice and are not inferred when the data is missing.
- Purchases: subscription product, entitlement status, transaction identifiers, renewal or expiration status, and restore history. Apple processes your payment details; we do not receive your card information.
- Device and diagnostics: account and installation identifiers, app version, push-notification tokens, feature-operation events, sync and call diagnostics, crash information, and performance data used to deliver and improve reliability.
Biometric data (special handling)
Your face photos and voice sample are biometric data. We ask for explicit, separate consent before collecting them. They are encrypted at rest (AES-256-GCM) and used only to render your future-self portrait and to synthesize your future self's voice. We do not sell biometric data, use it for advertising, or share it except with the processors below that perform those specific functions.
How we use your data
We use your data to provide and secure the service: to authenticate your account, render your future-self identity, power messages and calls, synchronize health data, show health and activity evidence, organize Investigations, personalize what matters today, maintain your subscription, deliver notifications you permit, and diagnose reliability problems. We do not sell your data, use it for third-party advertising, or track you across other companies' apps or websites. Your Echo is a wellness product — it is not a medical device and does not provide diagnosis or treatment.
Connected wearable accounts, including WHOOP
Connecting a wearable account is optional. If you choose to connect WHOOP, we use WHOOP's OAuth authorization screen to ask for access to the data categories you select. Depending on the permissions you approve, WHOOP may provide profile and body measurements, physiological cycles, recovery and strain data, sleep, workouts, heart rate, HRV, resting heart rate, timestamps, scores, and related summaries. We do not receive your WHOOP password.
We use connected wearable data only to synchronize and display your health and activity history, calculate trends and evidence, personalize your future-self messages and calls, support Investigations you approve, and keep the connection reliable. We do not sell WHOOP data, use it for advertising, or allow it to be used to target advertising. Your Echo only requests data that is relevant to features available in the app.
Access and refresh tokens are stored encrypted on our servers and are not exposed to the mobile app. You can disconnect WHOOP in Your Echo's Settings or revoke access from WHOOP. Disconnecting stops future collection and removes the stored connection credentials. Previously imported records remain in your account history until you delete your account or ask us to delete them, so your past trends and conversations do not disappear unexpectedly.
WHOOP separately controls the data in your WHOOP account. Its practices are described in the WHOOP Privacy Policy.
Who processes your data
We use a small set of third-party providers strictly to deliver features you trigger. Connected wearable providers, including WHOOP when you authorize it, supply the data you ask them to share. Other service providers process only the data needed to operate the feature described below. For questions about the current provider list, email support@yourecho.xyz.
- Language AI — generates your future self's written and spoken responses and helps organize Investigation context.
- Voice AI — voice cloning, speech synthesis, and transcription.
- Image AI — your future-self portrait.
- Encrypted database and storage — your account, transcripts, and media.
- Real-time call infrastructure — voice calls between you and your future self.
- Wearable connections — WHOOP and other providers you explicitly connect supply authorized health and activity data and connection events.
- Research and source services — retrieve or verify linked public sources used in an Investigation.
- Reliability and diagnostics — identify crashes, failed syncs, call failures, and performance problems.
Retention & deletion
We keep your data while your account is active. You can delete your account at any time from Settings; deletion removes your stored records, your generated media, and your cloned voice from our systems and our voice provider. Deleting your account also removes stored wearable credentials and imported wearable records, and we attempt to revoke active provider access where the provider supports it. Some logs may persist briefly in backups before rotating out.
Your rights
Depending on where you live (including under the EU GDPR and India's DPDP Act), you may have the right to access, correct, export, or delete your data, and to withdraw consent. You can exercise access, export, connection withdrawal, and deletion in the app, or contact us below.
Security
Data is encrypted in transit and at rest; biometric blobs are additionally sealed with per-record envelope encryption. No system is perfectly secure, but we limit collection, access, and retention to reduce risk.
Children
Your Echo is not intended for anyone under 18, and we do not knowingly collect their data.
Changes & contact
We may update this policy; we will revise the date above and, for material changes, notify you in the app. Questions or requests: support@yourecho.xyz.
Data controller
Your Echo is operated by Dreamers and Doers IT Solutions Private Limited, a company incorporated in India. For privacy questions, data-subject requests, or any other matter covered by this policy, write to support@yourecho.xyz.