Your Echo
Privacy Policy
Last updated 13 September 2026
Your Echo is a private conversational health and wellness companion. To provide that experience it handles some of your most personal information — including health data and conversations. This policy explains what we collect, why, who processes it on our behalf, and the control you have over it.
What we collect
- Account and profile: your name, email address, age, sex for health calculations, height and weight, and the priorities or goals you choose to share.
- Health & activity data: with your permission, data from Apple Health and wearable accounts you choose to connect. Depending on the source and permissions you approve, this can include workouts and their recorded laps or intervals, heart-rate samples during the day and night, HRV, resting heart rate, recovery and strain scores, sleep, steps, active energy, body measurements, menstrual-flow records, and workout routes or precise location when a recorded workout includes them.
- Conversations, calls, and Investigations: messages, call audio processed to conduct a live call, call transcripts and recaps, questions, responses, cited sources, and structured facts or findings derived from the context you provide.
- Files and images you upload: food photos, PDFs, laboratory reports, medical reports and images, their original files, extracted text or reported measurements, source references, and summaries. Estimated food portions and nutrition are labeled as estimates. A medical image or report is sensitive health information; an AI summary is not a clinical diagnosis.
- Notes, memories, and specialists: saved topic notes and revisions, relevant facts from your conversations, goals and plans, specialist instructions, and the note context attached to a conversation. These records help you continue a topic later and are associated with your account.
- Sensitive context you choose to provide: for high-trust features, information such as medication or reproductive-health context. These features require an explicit choice and are not inferred when the data is missing.
- Purchases: subscription product, entitlement status, transaction identifiers, renewal or expiration status, and restore history. Apple processes your payment details; we do not receive your card information.
- Device, usage, and diagnostics: account and installation identifiers, app version, push-notification tokens, coarse feature-interaction events, sync and call diagnostics, crash information, and performance data used to deliver and improve reliability.
How we use your data
We use your data to provide and secure the service: to authenticate your account, power messages and calls, synchronize health data, show health and activity evidence, build and update your plans, organize notes and Investigations, extract and explain uploaded information, personalize what matters today, maintain your subscription, deliver notifications you permit, and diagnose reliability problems. We do not sell your data, use it for third-party advertising, or track you across other companies' apps or websites. Your Echo is a wellness product — it is not a medical device and does not provide diagnosis or treatment.
To provide AI features, we send relevant conversation content, selected saved context, and the health information or uploaded material needed for the request to our AI service providers. This processing is separate from connecting an external wearable or the optional Claude connector. Your Apple Health permission controls access to Apple Health; notification permission controls notifications. Neither is a substitute for disclosure of AI processing.
Published agents and creator invitations
When creator publishing is available and you choose to publish, the creator name, bio, agent approach, selected sources and other content you explicitly review are shared with the audience you select. Private conversations, notes and health records are not included in a publication. Each person who adds an agent gets their own private copy and context. Copies already accepted by others can remain in their accounts after you retire or delete your publication; deleting your account does not delete another person's private records.
Creator invitations associate acceptance with the recipient's signed-in account so app access can continue after download. For selected-recipient links we compare a keyed hash of the invited email with the verified sign-in email. Raw invitation tokens and recipient emails are not stored in the invitation records. Revoking a link prevents new acceptances; it does not erase access or private copies already accepted.
To show creators how their agents are used, we record when an account adds an agent, first has a qualifying conversation, and the dates of qualifying activity. Creators see weekly aggregate installation, activation, active-user and retention counts. Counts below ten are hidden and larger counts are rounded down to tens. They cannot view recipients' identities, conversations or health information through this dashboard. These records follow account export and deletion controls. Activity-date lists are bounded to recent history when updated; aggregate weekly snapshots and first-use dates may remain for the account lifetime.
Connected wearable accounts, including WHOOP
Connecting a wearable account is optional. If you choose to connect WHOOP, we use WHOOP's OAuth authorization screen to ask for access to the data categories you select. Depending on the permissions you approve, WHOOP may provide profile and body measurements, physiological cycles, recovery and strain data, sleep, workouts, heart rate, HRV, resting heart rate, timestamps, scores, and related summaries. We do not receive your WHOOP password.
We use connected wearable data only to synchronize and display your health and activity history, calculate trends and evidence, personalize Echo's messages and calls, support Investigations you approve, and keep the connection reliable. We do not sell WHOOP data, use it for advertising, or allow it to be used to target advertising. Your Echo only requests data that is relevant to features available in the app.
Access and refresh tokens are stored encrypted on our servers and are not exposed to the mobile app. You can disconnect WHOOP in Your Echo's Settings or revoke access from WHOOP. Disconnecting stops future collection and removes the stored connection credentials. Previously imported records remain in your account history until you delete your account or ask us to delete them, so your past trends and conversations do not disappear unexpectedly.
WHOOP separately controls the data in your WHOOP account. Its practices are described in the WHOOP Privacy Policy.
Connecting Your Echo to Claude (MCP connector)
Your Echo offers an optional connector that lets you ask Claude, the AI assistant made by Anthropic, about your own health data. The connector is off until you set it up. No data is shared through this connector until you start the connection yourself and approve it in the app. Anthropic may separately process data for Echo’s own AI features as described below.
How the connection is made. You add Your Echo as a connector inside Claude. Claude sends you to our approval screen, you approve the request inside the Your Echo app while signed in, and Claude receives an access credential scoped to your account only. Approval is per connection and it expires. You can see and revoke every connection in Settings inside the app at any time, which immediately stops all further access.
What Claude can read. Only these five categories, and only for your own account:
- Sleep: nightly duration, efficiency, sleep window, and stage summary.
- Heart measurements: heart rate variability, resting heart rate, and the recovery and readiness scores derived from them.
- Workouts: type, time, duration, average and maximum heart rate, distance, and energy.
- Activity and body measurements: daily step counts and body weight.
- Investigations: the questions Echo is looking into for you and the findings it has reached.
What this connector cannot read. Your conversations and messages with Echo, your call transcripts and recordings, the memories Echo keeps about you, your location or workout routes, your account credentials, and any other person's data. This is enforced at the database level: the connector holds a read-only credential that is granted access to specific columns of specific tables and is technically incapable of reading anything else, including for any account other than the one that approved the connection.
The connector cannot write. It can read the data listed above and nothing more. It cannot change, add, or delete anything in your account.
What Anthropic does with it. Data you request through the connector is delivered into your own Claude conversation and is handled under Anthropic's privacy policy and terms, not ours, once it arrives there. We do not sell your health data, we do not share it for advertising or marketing, and we do not use it for any form of use-based data mining. See Anthropic's Privacy Policy.
Revoking. Open Settings in the Your Echo app and remove the connection. Access stops immediately. Removing the connector inside Claude is also good hygiene, but the revocation in the app is what actually ends access. Deleting your account removes all connections as part of the deletion described below.
Who processes your data
We use a small set of third-party providers to operate the service and deliver its features. Connected wearable providers, including WHOOP when you authorize it, supply the data you ask them to share. Other service providers process only the data needed to operate the feature described below. For questions about the current provider list, email support@yourecho.xyz.
- OpenAI and Anthropic: process relevant messages, health evidence, saved context and model responses for Echo’s AI features. OpenAI also processes supported uploaded images and documents for extraction and explanation. Routing depends on the feature and service availability; Anthropic is used for some voice reasoning and as a configured fallback for supported written responses. See OpenAI’s Privacy Policy and Anthropic’s Privacy Policy.
- ElevenLabs and AssemblyAI: process audio and text for speech generation or transcription, depending on the voice feature and configured provider. A voice provider may retain conversation data under its service settings and terms.
- Supabase: authentication, database and private file storage for account records, health records, uploads, messages, notes, plans, transcripts and summaries.
- Vercel and LiveKit: application hosting and real-time call infrastructure. They process the network and content data needed to deliver requests and calls.
- Wearable connections — WHOOP and other providers you explicitly connect supply authorized health and activity data and connection events.
- Research and source services — retrieve or verify linked public sources used in an Investigation.
- Product analytics, reliability, and diagnostics — understand coarse feature usage and identify crashes, failed syncs, call failures, and performance problems.
- Claude connector (Anthropic): when you connect it yourself, delivers the sleep, heart, workout, activity and body measurement, and Investigation data listed above into your own Claude conversation. Off by default, revocable in Settings.
Product analytics
We use PostHog as a product analytics processor to understand coarse feature usage and reliability. We send a limited, allowlisted set of events and properties, such as the feature used, whether an operation succeeded, a coarse latency range, app version, and a pseudonymous account or installation identifier. We do not send health measurements, message text, call audio, call transcripts, or other free-form content to PostHog. We do not enable session replay or automatic event capture, and we do not use analytics data for advertising or tracking across other companies' apps or websites.
As with ordinary internet requests, service providers may process network information such as an IP address when a request reaches their systems. We do not use that information for precise-location personalization, advertising, or cross-app tracking.
Retention & deletion
We keep your data while your account is active. You can delete your account at any time from Settings; deletion removes your stored account and profile records, messages, transcripts, plans, notes and revisions, uploaded files, extracted readings and summaries, Investigations, and other service records. Deleting your account also removes stored wearable and Claude connector credentials and imported wearable records, and we attempt to revoke active provider access where the provider supports it. File and external-processor deletion can require retries after the account records are removed; pending work is retained securely until it can complete. Restricted backups and records required for legal, security or transaction purposes may remain under the applicable retention requirements. Deleting Echo does not delete source records in Apple Health or a wearable provider, or copies you have exported to another service.
Your rights
Depending on where you live (including under the EU GDPR and India's DPDP Act), you may have the right to access, correct, export, or delete your data, and to withdraw consent. You can exercise access, export, connection withdrawal, and deletion in the app, or contact us below.
Security
Data is encrypted in transit and at rest. We use access controls and additional safeguards for sensitive health and conversation records. No system is perfectly secure, but we limit collection, access, and retention to reduce risk.
Children
Your Echo is not intended for anyone under 18, and we do not knowingly collect their data.
Changes & contact
We may update this policy; we will revise the date above and, for material changes, notify you in the app. Questions or requests: support@yourecho.xyz.
Data controller
Your Echo is operated by Dreamers and Doers IT Solutions Private Limited, a company incorporated in India. For privacy questions, data-subject requests, or any other matter covered by this policy, write to support@yourecho.xyz.