In short: Your journal entries are private. We don't sell your data, we don't track you, and we don't show ads. Your words belong to you.
1. What We Collect
When you create an account, we collect:
Email address — to create your account and send verification codes
Password hash — your password is encrypted (PBKDF2-SHA256, 100,000 iterations) and never stored in plain text
Profile information — your name, goals, fears, and vision, which you provide during onboarding
When you use the app, we store:
Journal entries — the text you write or speak
AI reflections — responses generated by AI on your behalf
Voice data — if you clone your voice, we store voice IDs provided by our voice provider (ElevenLabs). We do not store raw audio recordings.
2. What We Do NOT Collect
We do not collect, use, or share:
Analytics or tracking data
Device fingerprints or browser fingerprints
Location data
Contact lists or social media data
Advertising identifiers
Any data for third-party marketing or sales
3. How Your Data Is Used
Your data is used exclusively to:
Provide the core FutureEcho experience (journaling, AI reflection, voice playback)
Generate AI reflections using your personal context (goals, fears, vision)
Create and manage your account
Text is sent to AI providers (Groq, Cloudflare Workers AI) solely to generate reflections and Q&A responses. Voice cloning is processed through ElevenLabs. We do not use your data to train AI models.
4. Who Has Access to Your Data
Your journal entries are scoped to your account only. No other user can access them. FutureEcho staff do not read your entries. We do not sell, rent, or share your data with any third party for commercial purposes.
5. Third-Party Services
FutureEcho uses the following services, each with their own privacy policies:
Your data is stored for as long as your account is active. You can delete all your data at any time from the app's Settings page. Once deleted, data is permanently removed and cannot be recovered. We do not retain backups of deleted data.
7. Security
We use industry-standard security practices:
Passwords are hashed with PBKDF2-SHA256 (100,000 iterations, random salt)
Session tokens use HMAC-SHA256 signed JWT with expiration
All data is transmitted over HTTPS (TLS 1.3)
Database access is scoped per-user at the application level
8. Children's Privacy
FutureEcho is not intended for use by anyone under the age of 13. We do not knowingly collect personal information from children.
9. Changes to This Policy
If we update this policy, we will notify you within the app and update the "Last updated" date above. Continued use of FutureEcho after changes constitutes acceptance of the updated policy.
10. Contact
If you have questions about this policy or your data, contact us at: [email protected]