Data

What we store

The data EchoPilot keeps for accounts, audits, free scores and integrations, how long each is kept, and how deletion works.

Updated

A plain-language map of the data EchoPilot holds and for how long. The privacy policy is authoritative; every number here comes from it or from a constant in the product.

What is collected

  • Intake data you submit. Business name, website, kind of business, city, country, ticket band, Google listing, phone, address, social handles, main service, ad-spend band, newsletter and Search Console answers.
  • Extracted public business data. For each rule, the facts the check read: titles, counts, flags, short snippets. Every fetch is logged with its outcome, reason and duration; full page bodies are not kept. Sources are the website (at most 60 crawled pages per audit, honouring robots.txt), DNS, PageSpeed, search results, Google Places details and public reviews, public social-profile metadata, directory listings and AI-visibility queries.
  • Generated content. Memos, their actions and your open/done/dismissed status on each, and, when they ship, drafted posts with your approval or rejection of each item.
  • Account data. Email address, Google account identifier if you use Google sign-in, hashed sign-in links (15-minute expiry, single use), hashed sessions, tenant membership, plan and billing state.
  • Free score data. The domain, the email address you entered, the network address used for rate limiting, and the result.
  • Connected integration tokens. The Google Business Profile refresh token, encrypted with AES-256-GCM with a per-row IV, plus the account email, the chosen location and the last snapshot counts.
  • Share tokens. Only the SHA-256 hash of each public link.
  • Payment data. Stripe processes payments; EchoPilot receives a customer id, subscription status, plan, interval and period dates, never full card numbers.
  • Language-model usage. Per call: model, prompt file, token counts, estimated cost and status. Prompts contain extracted business text, never your credentials.
  • Technical data. IP address and its country as passed by Cloudflare, user agent, timestamps and request logs, for rate limiting, security and the territorial restriction.

Retention

Data Kept
Free score cached result 7 days (the page stops serving it), then the row goes with the address below
Free score email address 90 days, then the free-score row is deleted
Audit history, evidence, memos for the life of the account
A business you remove hidden; its history kept until account deletion or an explicit request
Connected tokens until you disconnect or delete the account
Data after a cancellation takes effect 30 days, then business data is purged and the sign-in remains
Account data after account deletion deleted or anonymised within 30 days
Payment records (at Stripe) 7 years (UK tax law)
Logs 90 days for the fetch log and event rows; process logs rotate after 14 days
Setup wizard drafts 14 days

How the periods are enforced

The 7-day free-score cache and the 30-day post-cancellation purge are enforced by the product itself: the result page reads only rows that have not expired, and the worker purges cancelled tenants on its hourly housekeeping pass. The same hourly pass runs a retention job that deletes free-score rows (the address, the network address and the link token) older than 90 days, and the per-fetch log and per-request event rows older than 90 days. Daily aggregate counts are kept without any personal data. The owner can run the same job by hand in a dry-run mode that only prints counts. Process logs on the server rotate daily and are kept for 14 days.

Deletion

  • Remove a business on the dashboard: it is hidden; audit history stays.
  • Cancel: business data is purged 30 days after the subscription ends unless a plan comes back; see Pause, cancel and delete.
  • Delete the account on /app/billing: cancels any subscription immediately, deletes every business, audit, memo, draft and integration, then the account. Invoices stay at Stripe.
  • Disconnect Google Business Profile on /app/integrations: the stored token is revoked immediately.
  • Revoke a share link on the audit report page: the URL returns 404 from then on.
  • Anything else, such as a specific business's history or a free-score record: email from your account address; the policy commits to an answer within one month.

Who processes it

Cloudflare (proxy, TLS, geolocation), Stripe (payments, billing portal), Google (sign-in, PageSpeed Insights, Places API), Anthropic (language-model classification of page text, review themes and drafts), a search-results provider (SerpApi or DataForSEO), Brevo (email), EchoRank (AI-visibility queries) and RackNerd (hosting, in Utah, United States). Personal data is not sold or used for advertising.

Cookies

Strictly necessary only: a session cookie when signed in and a short-lived cookie during Google sign-in or the Business Profile connection. No advertising or cross-site tracking.

Security in brief

TLS everywhere, hashed sign-in and share tokens, encrypted integration tokens, a database bound to the local host, nightly rotated backups. If a breach affects your data, you are notified and, where required, the UK ICO within 72 hours.

Still stuck? Email [email protected] and a person will answer.