Privacy policy

Last updated: 29 September 2026

Who is responsible

Benjamin Libor
Grünberger Straße 17
10243 Berlin, Germany
Email: ibo@allsite.pro

What Echo stores and why

  • Your account: your email address, your name and profile picture if you sign in with Google, and the time you signed up. We need these to let you sign in (Art. 6(1)(b) GDPR, performing our contract with you).
  • Sign-in sessions: a session record with your IP address and browser name, so you stay signed in and we can spot misuse. Sessions expire after 7 days without use.
  • What you set up and what Echo finds: your brand, website, competitors, prompts, the AI answers Echo collects, and the numbers calculated from them.
  • Usage and costs: how many prompts were run and their estimated cost, to enforce the limits of your plan.
  • Abuse protection: for sign-in emails and runs, we count requests per email address, IP address or account for up to two days, to stop anyone flooding an inbox or the service (Art. 6(1)(f) GDPR, our legitimate interest in a secure service).
  • Plan and billing: your workspace's plan, its status (trial, active, cancelled), the dates it renews or ends, and Stripe's customer and subscription IDs, so Echo applies the right limits (Art. 6(1)(b) GDPR). Echo never sees or stores your card number. Invoices are kept as long as tax law requires (Art. 6(1)(c) GDPR; in Germany currently up to 10 years).
  • Websites Echo reads: to suggest actions and watch competitors, Echo reads public pages of your brand's website and of the competitors' websites you add (respecting their robots.txt), and keeps the page text when it changes for 12 months. These pages can contain names, for example in customer quotes; Echo doesn't look for personal data in them (Art. 6(1)(f) GDPR, our legitimate interest and yours in understanding a market from public sources).
  • The free AI score (/score): the website you enter, your first and last name, your email address, the result and the time. We email you the result, and Echo's owner gets a copy to follow up about it (Art. 6(1)(b) GDPR for sending the result you asked for, Art. 6(1)(f) GDPR for the follow-up; you can object any time by email). To stop misuse, we count scans per IP address for an hour and per email address for a day. Anyone with the report's link can see the result, but never your name or email address. Scans are deleted after 24 months, or sooner if you ask.
  • Visits from AI crawlers: when a workspace connects its website to AI crawlers (a snippet or a log file), the website sends Echo only visits whose user agent names a known AI crawler or assistant (such as GPTBot, ClaudeBot or PerplexityBot). Echo stores the crawler's name, the page's path without its query string, the status code and the time; everything else is dropped before it's stored. No IP addresses, no cookies and nothing about the website's human visitors. echo-aeo.com records the same four facts about AI crawlers that visit it. The single visits are deleted after 90 days; the daily counts per crawler stay while the brand exists (Art. 6(1)(f) GDPR, the workspace's legitimate interest in knowing how AI assistants read its website).
  • The Echo tag on a customer's website: when a workspace adds the Echo tag (a script) to its website, Echo processes data about that website's visitors on the workspace's behalf, as its processor (Art. 28 GDPR). For each page view, form sent or marked click the browser sends the page's address, the page it came from, the event's name and its browser details; Echo keeps the page's path, where the visit came from (such as "ChatGPT" or "Google"), UTM tags, the country (from Cloudflare, never the city), the kind of device and a visitor code. The code is made from a random key of the day, the website, the IP address and the browser; the key is deleted after two days, so the code can't be traced back to anyone, and the IP address itself is never stored. No cookies, nothing stored in the visitor's browser, never what people type into forms, and nothing is sent by browsers that ask not to be tracked (Do Not Track, Global Privacy Control). Single events are kept 90 days in Cloudflare Workers Analytics Engine; daily counts stay 25 months.
  • Tags and the cookie banner through the Echo tag: when a workspace enters the IDs of its own marketing tags (such as Google Analytics, Google Ads, the Meta pixel or the LinkedIn Insight Tag), the Echo tag shows the workspace's cookie banner and loads those tags in the visitor's browser only after the visitor agrees. The visitor's choice is kept in their own browser for six months; Echo doesn't receive or store it. What those tags then collect goes straight to their providers, under the workspace's own agreements with them.
  • Conversions sent to ad platforms: only when a workspace switches it on, as its processor (Art. 28 GDPR). For a form sent or a marked click on the workspace's website, if the visitor agreed to marketing (or analytics for Google Analytics), Echo passes the event, the page, the visitor's IP address and browser details and the platforms' own browser IDs straight on to Meta, LinkedIn or Google Analytics while handling the request, and stores none of them. For confirmed form sign-ups and won deals from HubSpot or Attio, only when the workspace switched on hashed emails, Echo sends a one-way SHA-256 hash of the email address (never the address) with the deal's amount. Echo keeps a log of what it sent (the event's name, platform, time and whether it arrived, without any personal data) for 90 days, and for deals only the hash of the contact's email.
  • Company visitors: only when a workspace switches it on for a brand (it's off by default), Echo also finds out which company a visit to that brand's website comes from, as the workspace's processor (Art. 28 GDPR; the workspace relies on its legitimate interest, Art. 6(1)(f) GDPR, and tells its visitors in its own privacy policy). For this the visitor's IP address is sent to Snitcher (see below), which answers with the company that uses the network, if any. Echo keeps only the company (name, website, industry, size, country and its LinkedIn page) with the visit's pages, source and times, and a record that the address's range belongs to that company or to no company, under a one-way code for 30 days. Echo never stores the IP address or the range, and never identifies people: home, mobile and cloud connections show no company. Browsers that ask not to be tracked are never looked up. Company visits are kept 400 days.
  • Emails we sent you: which weekly report or alert went out and when, so none is sent twice.
  • Team invites: when a workspace owner invites someone, we store the invited email address, who sent the invite and when, and send one invite email (Art. 6(1)(f) GDPR, the owner's legitimate interest in working with colleagues). The invite is deleted when it's accepted or cancelled, and stops working after 7 days.
  • Customer stories: when a workspace asks one of its customers to approve a customer story, Echo stores, for that workspace, the customer contact's name, role and email address, the items shown to them, their answer per item and channel, their comments, the name and role they typed, the time, their IP address and browser name, and a PDF record of it. Echo sends the approval email, up to two reminders and the record on the workspace's behalf. For this data the workspace is the controller and Echo processes it on the workspace's instructions (Art. 28 GDPR); the workspace relies on its own legal basis, usually its legitimate interest in documenting the customer's consent to be named (Art. 6(1)(f) GDPR). The record is kept until the workspace deletes the customer, so it can show what was approved. Contacts can ask the workspace, or us, for access or deletion.
  • Email campaigns (leads): when a workspace uses email campaigns (Growth and Pro plans), Echo stores, for that workspace, the leads it adds: email address, name, company, website, role, notes and other columns it imports, where each lead came from and when they agreed to hear from the workspace. Echo also stores every mail it sent to a lead, the replies that come back to the sending address (forwarded to the workspace), and whether a lead unsubscribed, bounced or marked a mail as spam. For this data the workspace is the controller and Echo processes it only on the workspace's instructions (Art. 28 GDPR); the workspace needs the lead's consent or another legal basis for writing to them. The workspace can delete leads any time (Grow → Leads). Addresses that unsubscribed, bounced or complained are kept, with only that fact, so they're never emailed again; they're deleted with the workspace. A lead can unsubscribe with the link in every mail, and can ask the workspace, or us, for access or deletion.

Cookies and local storage

Echo sets one cookie: the session cookie that keeps you signed in. It's strictly necessary, so we don't ask for consent. Your browser also remembers your light or dark theme and whether the sidebar is open (local storage, never sent to us). There is no analytics, advertising or tracking of any kind.

Emails

We send sign-in links, and, if you keep them switched on, a weekly report and drop alerts about your brand. You can turn these off in Settings → Notifications, or with the unsubscribe link in every email. The workspace owner also gets billing emails (a trial ending soon, a failed payment), which belong to the contract and can't be turned off.

Services we use

These providers process data for us under data processing agreements:

  • Cloudflare (Cloudflare, Inc., USA) hosts the app and its database. Data may be processed outside the EU; Cloudflare is certified under the EU-US Data Privacy Framework and uses the EU Standard Contractual Clauses.
  • Resend (Resend, Inc., USA) sends our emails. It receives your email address and the content of the email. Email campaigns go through a separate Resend account: it receives the lead's email address, the mail and the replies to it, and the workspace's sending domain.
  • OpenAI (OpenAI, L.L.C., USA) answers the prompts and analyses the answers, websites and competitor changes. It receives your brand's name, website, description, competitors and prompts, and text from the websites Echo reads, but never your email address or name. Under OpenAI's API terms, this data isn't used to train their models. When you use the agent in the app, OpenAI also receives your messages, the files you attach, the Echo data the agent reads to answer, and your name and your workspace members' names (so you can assign work to them), never email addresses. OpenAI keeps these conversations for 30 days so a chat can continue, then deletes them. For email campaigns, OpenAI writes each mail from the lead's details (email address, name, company, website, role, notes), the campaign's goal and the earlier mails to that lead.
  • Your workspace's own OpenAI key, only if the workspace owner adds one (Settings → Usage): Echo stores the key encrypted and uses it for drafts, content briefs, the agent, email writing, customer stories and guideline checks. Those requests then go to OpenAI under your own OpenAI account and its terms, with the same data as above; Echo logs only their token counts and estimated cost. Removing the key deletes it at once.
  • Claude or ChatGPT (Anthropic PBC or OpenAI, L.L.C., USA), only if you connect Echo to your own Claude or ChatGPT (Settings → Connections): when you ask it something, it reads through Echo's connector what you can see in the workspace you chose (brands, actions, AI visibility, prompts and answers, competitors, SEO, performance, campaigns, drafts, brand voice and guidelines, asset names and links, and your members' names), with email addresses hidden. That data then sits in your chat with that assistant, under your agreement with Anthropic or OpenAI, which Echo doesn't control. Changes it suggests are stored in Echo as proposals only you see until you apply them. Echo stores the app's name, which person and workspace it acts for, hashed access tokens and a log of each request (the tool's name and time, kept 90 days). Disconnect any time in Settings → Connections.
  • Perplexity (Perplexity AI, Inc., USA) answers the prompts for Perplexity and Claude. It receives the prompts and the country they're asked from, nothing about you.
  • Google (Google Ireland Ltd.) answers the prompts for Gemini through the Gemini API, with the same data as Perplexity. On the paid Gemini API, Google doesn't use it to improve its products.
  • DataForSEO (dataforseo.com) runs the prompts as Google searches, to read Google's AI Overviews. It receives the prompts and the country and language they're searched in, nothing about you. For SEO it also receives your brand's and competitors' website addresses and the keywords you track, and it crawls the public pages of your website for the monthly site audit (respecting robots.txt).
  • Stripe (Stripe Payments Europe, Ltd., Ireland) handles payments, invoices and VAT. When you choose a plan, Stripe receives your name, email address, billing address, VAT ID if you enter one, and your payment details, which go straight to Stripe. Stripe processes them for us and, for fraud prevention and its own legal duties, as a controller itself (see stripe.com/privacy). Data may be processed in the USA under the EU-US Data Privacy Framework and the EU Standard Contractual Clauses.
  • Google (Google Ireland Ltd.) handles sign-in if you choose "Sign in with Google". Google tells us your name, email address and profile picture.
  • Google Analytics and Search Console, only if you connect them for a brand (Settings → Connections): Echo reads, read-only, your property's weekly visits by source, landing pages and key events, and your site's search clicks, impressions and positions by query and page. Echo keeps these weekly numbers for 25 months and deletes them when you disconnect (which also removes Echo's access at Google).
  • HubSpot (HubSpot, Inc.), only if the workspace owner connects it: Echo sends your Outreach leads (name, email, company, website, campaign, status, consent) and replies to your HubSpot account, and reads contacts' email opt-outs, deals (name, amount, dates, stage) and where contacts first came from. HubSpot processes this for you as your CRM. With Company visitors, "Add to HubSpot" also creates the visiting company (name, website, LinkedIn page) with a note of its visits.
  • Attio (Attio Ltd, UK), only if the workspace owner connects it: the same as HubSpot for your Outreach leads, replies and deals, and, with Company visitors, "Add to Attio" creates the visiting company with a note of its visits. Attio processes this for you as your CRM.
  • Snitcher (Snitcher B.V., Netherlands), only for brands that switch on Company visitors: receives the IP address of a visit to that brand's website and answers with the company behind the network. Snitcher processes it in the EU under a data processing agreement; Echo doesn't send the address again for 30 days once its range is known.
  • Google Tag Manager, only if you connect it for a brand (Insights → Tracking setup): Echo stores an access token (encrypted) that can edit your containers, reads your accounts, containers, tags and triggers, and adds tags and triggers in a new workspace when you ask. It never publishes: you do that in Tag Manager. Disconnect removes Echo's access at Google.
  • Meta, LinkedIn and Google Analytics as recipients of your conversions, only if you switch them on (Settings → Tracking): see "Conversions sent to ad platforms" above. Your Meta Conversions API token and your Google Analytics Measurement Protocol secret are stored encrypted. These providers receive the data as your processors or as controllers under your own terms with them.
  • LinkedIn (LinkedIn Ireland Unlimited Company), only if you connect it for a brand: Echo stores an access token (encrypted) to publish the posts you schedule, with their images or PDFs, and reads your name, profile picture, the company pages you administer and, for company-page posts, their statistics. Remove an account in Grow → Social any time.
  • Meta (Meta Platforms Ireland Ltd.), only if you connect Meta ads for a brand: Echo stores an access token (encrypted) with read-only access to your ad accounts (ads_read) and reads your name, the ad accounts you can see, and per campaign and day the spend, impressions, clicks and conversions. Echo keeps these daily numbers for 25 months and deletes them when you disconnect (which also removes Echo's access at Meta). Echo never creates or changes ads.
  • Forms: when someone signs up through a brand's form, Echo stores what they entered, the consent text they agreed to, the time, and a one-way hash of their IP address, and emails them a confirmation link. Only after they confirm do they become a lead the brand may email.
  • Webhooks, the API, Zapier and n8n, only if the workspace owner sets them up (Settings → API and webhooks): Echo sends the events you pick (for example a form sign-up with the lead's name and email, a reply, an action) to the addresses you enter, and lets tools holding one of your API keys read and change the data that key allows. You choose these recipients; they process the data for you or under your own terms with them. Echo stores only a fingerprint of each API key, encrypts webhook secrets, and keeps the events and deliveries for 30 days. Playbooks email only leads who agreed to hear from you.

How long we keep data

We keep your data while you have an account. When you delete your account (Settings → Account → Delete account), we delete your account, the workspaces only you use (with their brands, prompts, answers and usage) and your memberships in other workspaces right away. A workspace other people use stays until its owner deletes it. The database's automatic point-in-time backups expire within 30 days.

Your rights

You have the right to access your data, to have it corrected or deleted, to restrict or object to its processing, and to receive it in a portable format. Most tables in Echo can be exported as CSV. For anything else, write to the email address above. You can also complain to a data protection authority, for example the Berliner Beauftragte für Datenschutz und Informationsfreiheit (Berlin Commissioner for Data Protection and Freedom of Information).

See also the imprint.