Legal
Privacy Policy
Last updated: August 7, 2026
This Privacy Policy explains how Echoia ("Echoia", "we", "us") collects, uses, stores, shares and protects information when you use our website, applications and services (together, the "Service") — a social media management platform that lets you publish content, manage comments and direct messages, and analyze performance across the social media accounts you choose to connect.
The data controller for the personal data described in this policy is Ilies Ziyad EL AYYADI, sole trader (entrepreneur individuel) trading as STUDIO DA, registered in France under SIREN 104 686 118 (SIRET 104 686 118 00019), whose registered address is 60 rue François Ier, 75008 Paris, France. Echoia is a service operated by that business. For any privacy question or request, contact contact@echoia.io.
1. Information we collect
Account information. When you create an Echoia account we collect your name, email address, password (stored as a salted hash — we never see or store your plaintext password) and, optionally, a profile picture and workspace name. If you sign in with Google, we receive your name, email and profile picture from Google.
Connected social media accounts. When you connect a social platform (such as Instagram, Facebook, YouTube, TikTok, LinkedIn, X, Threads, Bluesky, Pinterest or Google Business Profile), we receive and store, with your explicit authorization through that platform's consent flow:
- Access credentials (OAuth access and refresh tokens, or an app password you provide for platforms that use one). These are stored securely and used exclusively to perform the actions you request.
- Profile metadata for the connected account: account/page name, handle, avatar, account identifier, and audience statistics such as follower counts.
- Content and engagement data needed to power your inbox and analytics: posts you publish through Echoia, comments and replies on your content, direct messages sent to your connected accounts, and related engagement metrics.
Content you create. Drafts, scheduled posts, media you upload, internal tags and notes, reply templates, and any other content you produce inside the Service.
Payment information. Payments are processed by Stripe. We never receive or store your full card number; we keep only your subscription status, plan, billing country and invoice history.
Usage and technical data. Log data (IP address, browser type, pages viewed, timestamps), device information, and feature-usage metrics (for example how many scheduled posts or AI messages your plan has consumed). We use this to operate quotas, secure the Service and improve the product.
Support communications. Messages you send to our support channels, including their content and your contact details.
2. How we use your information
- To provide the Service: publishing your content, syncing your inboxes, computing analytics, and operating the features you use.
- To operate the AI features of your plan, both the ones you invoke and the automatic classification of your inbox — see section 4.
- To authenticate you and keep your account secure (including fraud and abuse prevention).
- To process payments, enforce plan quotas and manage subscriptions.
- To respond to support requests.
- To send transactional emails (account, billing, security). Product or marketing emails are only sent with your consent and always include an unsubscribe link.
- To understand aggregate product usage and improve the Service.
- To comply with legal obligations.
We do not sell your personal data. We do not use your data, or data received from connected platforms, for advertising. We do not use your content or data received from connected platforms to train machine-learning models.
Legal bases
Under the GDPR, each purpose above rests on one of the following bases.
- Performance of our contract with you (Article 6(1)(b)): operating the Service, publishing what you schedule, syncing your inboxes, computing your analytics, running the AI features of your plan, processing payments and answering support requests.
- Our legitimate interests (Article 6(1)(f)): keeping the Service secure, preventing fraud and abuse, enforcing plan quotas, and understanding aggregate usage to improve the product. We balance those interests against your rights, and you may object at any time as described in section 10.
- Your consent (Article 6(1)(a)): product and marketing emails, which you can withdraw at any time without affecting the Service.
- Legal obligation (Article 6(1)(c)): accounting and tax records, and responses to lawful requests from public authorities.
3. Data received from social media platforms
Data obtained through platform APIs is used solely to provide the features you request, is retained no longer than necessary for that purpose, and is never sold or transferred to third parties except as required to operate the Service (see section 6) or by law. Our use of each platform's data complies with that platform's terms, including:
- Meta Platforms (Instagram, Facebook, Threads): we comply with the Meta Platform Terms and Developer Policies. You can revoke Echoia's access at any time in your Facebook or Instagram security settings, or by disconnecting the account in Echoia.
- Google (YouTube, Google Business Profile): Echoia's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Echoia uses the YouTube API Services; by connecting a YouTube account you also agree to the YouTube Terms of Service and the Google Privacy Policy. You can revoke Echoia's access at any time via your Google security settings.
- Other platforms (TikTok, LinkedIn, X, Pinterest, Bluesky and others we may add): we access only the scopes you approve during connection and comply with each platform's developer terms. Access can always be revoked from the platform's own settings or by disconnecting the account in Echoia.
Disconnecting an account in Echoia deactivates its credentials immediately; associated cached content is deleted according to the retention rules in section 8.
4. AI features
Some features use large language models. The relevant content is transmitted to our AI infrastructure provider (OpenRouter) for processing, under contracts that prohibit using it for anything other than returning the result, including training their models. There are two kinds, and the difference matters.
Features you invoke. Drafting a reply, rewriting a caption, generating ad copy, answering a question in the assistant. Nothing is sent until you press the button.
Automatic classification. Comments and messages that arrive in your inbox are classified as positive, negative or neutral and tagged by topic (question, complaint, suggestion) as they are synced, without an action on your part. This is what lets the inbox show you what needs answering first, and it is the feature the product is built around. The text of the comment or message is sent for that classification.
These classifications are labels attached to a message to help you sort your inbox. They produce no decision about anyone, no score, no automated action, and nothing is ever sent or published without you pressing send.
5. People who contact you on the platforms you connect
When someone comments on one of your posts or sends a message to one of your connected accounts, Echoia stores that comment or message so it can appear in your inbox. That includes their display name, their public profile picture, the identifier the platform assigns them, and what they wrote. It also includes what section 4 describes: an automatic sentiment and topic label, and, if you use those features, the tags, private notes and groups you attach to a contact.
Those people are not Echoia users and have no account with us. We process their data on the basis of our legitimate interest, and yours, in letting a business read and answer the messages sent to it — the same thing the platform's own inbox does, in one place rather than five. We never use it for advertising, never sell it, never enrich it with data from elsewhere, and never share it beyond the processors listed in section 6.
This data is deleted when you disconnect the account it came from, or when you delete your Echoia account, as described in section 8. If you are one of those people and want to know what we hold or have it deleted, write to contact@echoia.io and we will act on it, though the copy held by the platform itself is outside our control and must be addressed to them.
6. How we share information
We share personal data only with:
- Service providers (processors) that operate parts of the Service on our behalf. Each is bound by a data-processing agreement and acts only on our instructions:
- Render — application hosting (Frankfurt, Germany)
- Neon — managed PostgreSQL database (Frankfurt, Germany)
- Upstash — message queue carrying platform webhook payloads
- OpenRouter — AI inference (section 4)
- Cloudinary — storage and delivery of the media you upload
- Stripe — payments
- Resend — transactional email
- The social platforms you connect — when you publish or reply through Echoia, the content is transmitted to the platform you targeted, where the platform's own terms and privacy policy apply.
- Your workspace members — content, inbox items and analytics inside a workspace are visible to the teammates you invite, according to the roles you assign.
- Authorities, when required by applicable law, and successors in the event of a merger or acquisition (we would notify you before your data becomes subject to a different privacy policy).
7. International transfers
We are based in the European Union, and some of our service providers process data in the United States or other countries. Where personal data leaves the European Economic Area, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses or an adequacy decision (including the EU–US Data Privacy Framework where the provider is certified).
8. Data retention
- Account data: kept while your account is active.
- Platform credentials: for Facebook, Instagram and Threads, disconnecting an account stops the platform sending us anything further and erases its tokens immediately. For the other platforms, disconnecting deactivates the account and its tokens are erased when you delete your Echoia account.
- Synced inbox content (comments, messages, contact profiles): for Facebook, Instagram and Threads, deleted when you disconnect the account. For the other platforms, kept while the account remains connected so your inbox stays usable, and deleted with your account. Your own posts and your follower history are kept in both cases: they describe your account, not another person, and no API can rebuild them.
- Uploaded media: deleted from storage after successful publication, or when you delete the draft that references it.
- Account deletion: when you delete your Echoia account, personal data is deleted or irreversibly anonymized within 30 days, except the minimum we must retain for legal obligations (for example invoices, kept for the legally required period).
9. Security
We protect your data with industry-standard measures: encryption in transit (TLS) and at rest, hashed passwords, scoped OAuth tokens, workspace-level access control, and the principle of least privilege for our own systems. No method of transmission or storage is 100% secure, but we work continuously to protect your information, and we will notify you and the competent authority without undue delay in the event of a personal data breach that affects you, as required by law.
10. Your rights
If you are in the European Economic Area, the United Kingdom or Switzerland, you have the right to access, rectify, delete, and export your personal data, to restrict or object to certain processing, and to withdraw consent at any time where processing is based on consent. Similar rights may apply under other laws (for example the CCPA in California, which also entitles you to know that we do not sell or share your personal information).
To exercise any of these rights, email contact@echoia.io. We respond within 30 days. You also have the right to lodge a complaint with your local supervisory authority (in France, the CNIL at cnil.fr).
11. Cookies
The Service uses strictly necessary cookies only: session authentication, security (OAuth state), and your interface preferences. We do not use third-party advertising or cross-site tracking cookies. See our Cookie Policy for the full list.
12. Children
The Service is not directed to children under 16, and we do not knowingly collect data from them. If you believe a child has provided us personal data, contact us and we will delete it.
13. Changes to this policy
We may update this policy as the Service evolves. For material changes we will notify you by email or through the Service before the change takes effect. The "Last updated" date at the top always reflects the current version.
14. Contact
Ilies Ziyad EL AYYADI, sole trader trading as STUDIO DA — 60 rue François Ier, 75008 Paris, France — SIREN 104 686 118 — contact@echoia.io