Echoic

Privacy policy

Last updated 2026-09-23

Echoic is run by Harsh Todi, trading as Echoic, based in India ("we", "us"). This page says what we collect when you use echoic.io, what we do with it, and how to get it removed. We collect as little as the product needs to work.

What we collect

When you run a free scan:

When you give us your email to open or receive a result, we store that email next to the scan.

When you buy the audit, we store the payment reference, the amount, the currency, the domain and the email the order belongs to. Card and billing details go to our payment provider and never reach us.

When you book a call, the booking tool collects your name, email and anything you type into the form.

When you email us, we keep the conversation.

When you browse the site, we count page views, clicks and the steps of the scan and checkout (for example "scan started" or "checkout started"), with the page address, the referring site, your browser type and your rough location from your IP. This runs in cookieless mode: nothing is stored on your device, the IP is not kept, and visits are counted with a hash that is reset every day, so we cannot follow you from one day to the next or tell who you are. We never send your email address to our analytics.

What we do not collect

Result links are public to anyone with the link

Every scan gets a result page at an address like echoic.io/r/…. The address is long and random, so it cannot be guessed, but anyone you share it with can open it. The page shows the site that was scanned, the questions, the AI answers and the fix. It does not show your email.

Scans are of public websites and public AI answers. Do not scan a site whose results you would not want visible to someone holding the link. If you want a result page taken down, email us and we will delete it.

Why we use it

The legal basis is performing the service you asked for, our legitimate interest in preventing abuse and in understanding how the site is used (with no cookies and no way to identify you), and legal obligation for payment records.

Who else handles it

We use a small set of providers to run the service. Each one only receives what it needs for its job:

Some of these providers are outside India, including in the United States. By using the service you understand your data may be processed there.

How long we keep it

We keep scans, emails and order records until you ask us to delete them. Payment records may need to be kept longer where tax law requires it; we will tell you if that applies.

Your rights

You can ask us to show you what we hold about you, correct it, delete it, or stop emailing you. Email harsh@echoic.io from the address in question, or tell us the domain you scanned. We reply within 30 days, usually much sooner. These rights apply wherever you are, including under India's Digital Personal Data Protection Act and the GDPR.

If you think we got something wrong, tell us first and we will try to fix it. You can also complain to the data protection authority where you live.

Security

Connections to the site are encrypted. The database is not public, IP addresses are only stored as salted hashes, and payment details never touch our systems. No system is perfectly secure; if a breach affects your data, we will tell you.

Children

Echoic is a business tool and is not meant for anyone under 13. We do not knowingly collect data from children under 13, and if we learn we have, we delete it.

Changes

If this policy changes, we update the date at the top. If a change affects how we use data we already hold, we will email the people it affects before it takes effect.

Questions about any of this: harsh@echoic.io