← Back

Privacy Policy

Last updated: 30 April 2026 · Effective: 30 April 2026

Ekcho is built around pseudonymity. We deliberately collect the minimum personal data necessary to operate. We do not collect your real name. We do not sell your data.

1. Who Controls Your Data

Pratesh John Mathew ("Ekcho"), operating individually, is the Data Fiduciary under the Digital Personal Data Protection Act, 2023 (DPDP Act) and the Data Controller under the GDPR (for EU/EEA users).

Privacy enquiries: privacy@ekcho.net

General enquiries: info@ekcho.net

2. What Data We Collect

Account data

When you register, we collect your chosen voice name and a password (stored as a bcrypt hash — we never see your actual password). We do not require your real name, email address, phone number, or date of birth. We generate an internal pseudonymous identifier for your account.

Voice broadcasts

When you publish a broadcast, your audio recording is uploaded and stored on Supabase Storage. Your audio is processed by OpenAI Whisper to generate a transcript for content moderation. The transcript is stored alongside your broadcast.

Voice Game responses

If you participate in the Voice Game, we collect and store the following additional data:

  • Transcripts of your voice responses to each game question
  • A record of personalised follow-up questions generated for you and when you answered them
  • Timestamps of when each question was answered
  • A freedom verdict record if you reach that stage of your journey, and your confirmation or rejection of it

Voice Game responses are published as public voice broadcasts under your voice name. They are visible to all users of Ekcho. Your real identity is never attached to them.

Your responses are processed by OpenAI Whisper for transcription and by Anthropic Claude for generating your personalised questions. Neither OpenAI nor Anthropic use data sent via their APIs to train their AI models under their standard API terms. We do not sell your data. We do not use your data to train any AI models.

If you delete a Voice Game broadcast, it is removed from the feed and from public access. Your underlying response to that question is retained so your journey can continue. If you delete your account, all Voice Game data including responses and freedom verdict records are deleted within 30 days.

Voice anonymisation

Before your voice is recorded, Ekcho applies a real-time audio processing chain in your browser (highpass filter, tonal adjustment, subtle harmonic modification). This is designed to make your voice harder to identify — preserving your pseudonymity. This processing happens entirely on your device and the processed audio (not your raw voice) is what is uploaded and stored.

Push notifications

If you enable push notifications, your browser generates a push subscription token which is stored on our servers (Supabase). This token is used only to deliver notifications from Ekcho to your device. You can revoke this at any time in Settings → Notifications or in your browser/device settings. We do not share notification tokens with third parties.

My Voice Journal

Journal entries are private voice recordings stored in your account. They are never shared or processed for moderation unless you choose to publish them as a broadcast. If you generate a share link, the audio becomes temporarily accessible to anyone with the link for up to 7 days. Journal entries and their audio files are permanently deleted when you delete your account.

Listener rooms and voice neighbourhoods

When you join a listener room, your presence is recorded temporarily for the duration of the room. Neighbourhood membership is stored persistently. Your last active time and currently listening broadcast are stored so neighbours can see your presence. You can control visibility at any time.

Listening activity

We record which broadcasts you have listened to, your playback position, and completion status. This powers session memory and completion statistics. This data is associated with your pseudonymous account, not your real identity.

Private notes and messages

Messages between users are stored in our database and accessible only to the participants. We do not read private messages except as required for moderation investigations following a report.

Technical data

We collect IP addresses (for rate limiting and security), browser type, device type, and access logs. These are stored for up to 90 days for security purposes only.

Moderation data

Content moderation scores (from OpenAI Moderation API) are stored alongside broadcasts. If a broadcast is flagged or removed, we retain the moderation record for 2 years.

Analytics

We use Google Analytics 4 with IP anonymisation, subject to your cookie consent. Analytics data is aggregated and not linked to your identity.

3. Why We Process Your Data (Legal Basis)

Under the DPDP Act 2023 and GDPR, we process your data on these bases:

  • Contract performance: Account management, broadcasting, listening, messaging, journal storage
  • Legitimate interests: Platform security, fraud prevention, rate limiting, abuse detection
  • Legal obligation: Compliance with Indian law, court orders, government directions under the IT Act 2000
  • Consent: Optional features such as push notifications (you can withdraw consent at any time in Settings)

4. How Long We Keep Your Data

Data typeRetention period
Account profileUntil you delete your account + 30 days
Voice broadcastsUntil you delete the broadcast + 30 days
Voice journal entriesUntil you delete the entry or your account
Share links7 days from generation (then expired)
TranscriptsSame as broadcast
Listening historyUntil account deletion
Neighbourhood membershipUntil you leave the neighbourhood or delete account
Private messagesUntil account deletion or mutual deletion
Moderation records2 years
Security logs (IP)90 days

5. Who We Share Your Data With

We do not sell your personal data. We share data only with:

  • Supabase — database, storage, authentication. EU servers. Data Processing Agreement in place.
  • OpenAI — audio transcription (Whisper) and content moderation for published broadcasts. USA. Audio sent for transcription is not used for model training (OpenAI API data policy, March 2023 onwards).
  • ElevenLabs — AI voice synthesis used for AI Radio broadcasts. No user personal data is sent — only text scripts for AI-generated hosts.
  • Internet Archive (archive.org) — AI Radio audio files may be served from Archive.org infrastructure. No user personal data is transmitted.
  • Vercel — platform hosting. EU (London) region.
  • Google Analytics / Google Ads — usage measurement and advertising measurement, subject to your cookie consent. Anonymised IP. No personal data shared for advertising targeting.
  • Law enforcement / government authorities — when required by Indian law, court order, or government direction. We will notify you unless prohibited by law.

Ekcho currently has no paid features and does not use any payment processors.

6. International Data Transfers

Ekcho is operated in India. Your data may be transferred to servers outside India (EU via Supabase and Vercel, USA via OpenAI). These transfers are governed by Standard Contractual Clauses (SCCs) and Data Processing Agreements.

7. Your Rights Under the DPDP Act 2023

As a Data Principal under the DPDP Act 2023, you have the right to:

  • Access: Request a summary of your personal data we hold
  • Correction: Request correction of inaccurate data
  • Erasure: Request deletion of your personal data. You can do this directly in Settings → Delete Account.
  • Grievance redressal: Lodge a complaint with us — we respond within 72 hours and resolve within 30 days.
  • Nominate: Nominate another person to exercise your rights in the event of your death or incapacity

To exercise any right: privacy@ekcho.net. We respond within 72 hours.

8. Your Rights Under GDPR (EU/EEA Users)

If you are in the EU or EEA, you additionally have the right to:

  • Data portability (receive your data in a machine-readable format)
  • Object to processing based on legitimate interests
  • Lodge a complaint with your local data protection authority

9. Children's Privacy

Ekcho is not intended for children under 13. We do not knowingly collect personal data from children under 13. If you believe a child under 13 has created an account, contact us at info@ekcho.net and we will delete the account immediately.

10. Security

We protect your data using encryption at rest and in transit (TLS 1.3), Row Level Security (RLS) in our database ensuring each user can only access their own data, bcrypt password hashing, rate limiting on all authentication endpoints, and regular security reviews.

In the event of a data breach, we will notify you and the relevant authorities within 72 hours as required by the DPDP Act.

11. Grievance Officer

As required under the Information Technology Act, 2000 and DPDP Act 2023, our Grievance Officer is:

Name: Pratesh John Mathew
Email: privacy@ekcho.net
General: info@ekcho.net
Acknowledgement: Within 24 hours of receipt
Resolution: Within 15 days (as required by India IT Rules 2021)

12. Changes to This Policy

We will notify you of material changes to this Privacy Policy at least 14 days before they take effect, via in-app notification. The latest version is always available at ekcho.net/legal/privacy.