Echo Family — Privacy Policy
Last updated: September 3, 2026
The short version
Echo Family is a zero-knowledge family alert app. Your devices
encrypt everything sensitive end-to-end before it leaves
them. Our server stores ciphertext it cannot decrypt. We
collect no names, no emails, no phone numbers, no message contents,
and no analytics.
What the server sees
- Randomly generated pairing IDs and public keys (needed to route)
- Encrypted blobs (ciphertext). We cannot read them; only the paired
device holds the decryption key.
- An opaque Firebase Cloud Messaging push token used to wake a
paired device. It is deleted when a pairing expires or is removed.
- IP addresses in transient server logs for abuse protection,
retained briefly.
What the server never sees
- Message or notification plaintext — encrypted on the sending
device before it leaves
- Location plaintext — devices send end-to-end encrypted location
directly to the paired device during an SOS or an active, visible live
share. The server carries ciphertext only.
- Any account data — the app has no accounts
Permissions and what they are for
- Notification access (child/partner device): with
your explicit consent, shares the app a notification came from, its
title, its text and its time with your paired family member,
end-to-end encrypted. Revocable any time in Settings or system
settings.
- Location: used during an SOS, an active live
share, or safe zones you set up — always with a visible indicator on
the sharing device. A parent's own SOS also carries their location if
they allowed it.
- Camera: used only to scan the QR code when
pairing two devices. No photos or video are stored or transmitted.
- Notifications permission: to deliver alerts (SOS,
ring, location requests) from your family.
Payments
The optional Echo+ subscription is billed entirely through Google
Play. We never see or store your payment details. Google shares with
us only a purchase token and the subscription state so the app can
unlock premium features.
Child fairness
The child device always shows when the notification mirror or a
live location share is active. Live shares are time-limited and can be
stopped on the child device at any time.
Data deletion
Unpairing deletes all server-side blobs for the pairing. Because
the server holds only ciphertext it cannot decrypt, deletion is
immediate and complete. Push tokens expire automatically. Undelivered
messages are automatically deleted after 30 days.
Data safety summary (Google Play)
- No data collected — no personal info, no photos,
no files, no web history.
- App activity: none in plaintext; the server sees
only ciphertext it cannot decrypt.
- Device or other IDs: random pairing IDs and
opaque push tokens, used only for routing and waking devices, deleted
on unpair.
Contact
Questions: codesunicorn@gmail.com