Privacy policy
Last updated 2026-09-23
Echoic is run by Harsh Todi, trading as Echoic, based in India ("we", "us"). This page says what we collect when you use echoic.io, what we do with it, and how to get it removed. We collect as little as the product needs to work.
What we collect
When you run a free scan:
- The website address you enter, and what we read from its public pages to write questions about it.
- The questions we generated, the answers AI engines gave, the pages they quoted, and the fix we wrote.
- A one-way hash of your IP address, salted, so we can cap how many scans one address runs per day. We never store the IP itself.
When you give us your email to open or receive a result, we store that email next to the scan.
When you buy the audit, we store the payment reference, the amount, the currency, the domain and the email the order belongs to. Card and billing details go to our payment provider and never reach us.
When you book a call, the booking tool collects your name, email and anything you type into the form.
When you email us, we keep the conversation.
When you browse the site, we count page views, clicks and the steps of the scan and checkout (for example "scan started" or "checkout started"), with the page address, the referring site, your browser type and your rough location from your IP. This runs in cookieless mode: nothing is stored on your device, the IP is not kept, and visits are counted with a hash that is reset every day, so we cannot follow you from one day to the next or tell who you are. We never send your email address to our analytics.
What we do not collect
- No advertising or cross-site tracking. We do not run Google Analytics, ad pixels, heatmaps or session recording.
- No cookies set by us, and nothing stored in your browser by our analytics. There is no cookie banner because there is nothing to consent to.
- No selling or renting of your data, to anyone, ever.
- No marketing lists. We send the result email and one follow-up from Harsh. No newsletter, no drip.
Result links are public to anyone with the link
Every scan gets a result page at an address like echoic.io/r/…. The address is long and random, so it cannot be guessed, but anyone you share it with can open it. The page shows the site that was scanned, the questions, the AI answers and the fix. It does not show your email.
Scans are of public websites and public AI answers. Do not scan a site whose results you would not want visible to someone holding the link. If you want a result page taken down, email us and we will delete it.
Why we use it
- To run the scan and show you the result.
- To email you the result and, if you bought the audit, to deliver it and book the walkthrough.
- To stop abuse, since every scan costs us real money in AI and search fees.
- To reply when you write to us.
- To see which pages and steps work and where people drop off, so we can fix them.
- To keep records the law requires for payments.
The legal basis is performing the service you asked for, our legitimate interest in preventing abuse and in understanding how the site is used (with no cookies and no way to identify you), and legal obligation for payment records.
Who else handles it
We use a small set of providers to run the service. Each one only receives what it needs for its job:
- Vercel: hosts the website and processes requests.
- Supabase: our database, where scans, emails and orders are stored.
- OpenAI: reads the public pages of the scanned site and writes the questions and the fix. It receives the site content, not your email.
- DataForSEO: asks the questions on AI engines such as ChatGPT and Perplexity, and checks Google results. It receives the questions, not your email.
- Resend: sends our emails, so it receives your email address and the message.
- Dodo Payments: our merchant of record. It processes the payment and handles tax, receipts and refunds under its own privacy policy.
- Cal.com: runs the booking calendar embedded on the site, under its own privacy policy.
- PostHog (US cloud, hosted in Virginia): our cookieless analytics. It receives the page views, clicks and funnel steps described above, and the domain you scanned. It never receives your email.
Some of these providers are outside India, including in the United States. By using the service you understand your data may be processed there.
How long we keep it
We keep scans, emails and order records until you ask us to delete them. Payment records may need to be kept longer where tax law requires it; we will tell you if that applies.
Your rights
You can ask us to show you what we hold about you, correct it, delete it, or stop emailing you. Email harsh@echoic.io from the address in question, or tell us the domain you scanned. We reply within 30 days, usually much sooner. These rights apply wherever you are, including under India's Digital Personal Data Protection Act and the GDPR.
If you think we got something wrong, tell us first and we will try to fix it. You can also complain to the data protection authority where you live.
Security
Connections to the site are encrypted. The database is not public, IP addresses are only stored as salted hashes, and payment details never touch our systems. No system is perfectly secure; if a breach affects your data, we will tell you.
Children
Echoic is a business tool and is not meant for anyone under 13. We do not knowingly collect data from children under 13, and if we learn we have, we delete it.
Changes
If this policy changes, we update the date at the top. If a change affects how we use data we already hold, we will email the people it affects before it takes effect.
Questions about any of this: harsh@echoic.io