PRIVACY

Privacy Policy

With echOKs, you choose where, when, and for whom an Echo opens. This policy explains how we handle data in the app and on this website.

Last updated: 5 October 2026

01

Controller and contact

echOKs is provided by NOPECUBE LLC. For privacy questions and personal data requests, contact privacy@echoks.com.

02

Data we process

  • Account and verification: your Apple or Google sign-in identifier and information supplied by that provider, verified phone number, session details, and a server-side fingerprint of an installation identifier for the one-device rule.
  • Profile and content: username, display name, bio, profile photo, Echo text and media, chosen place and timing, comments, likes, reshares, follow relationships, and messages.
  • Preferences and safety: visibility, notification preferences; blocks, reports, moderation records, and security or rate-limit records.
  • When you opt in: a device push token for notifications; zone/day records for local participation and badges; account ID and UTC visit-day records linked to a hashed Google Place key for venue leadership.
  • Nearby alerts and personal reopening: the optional arrival-alert preference, private records of a recently alerted Echo and UTC day, and reopening cadence and timestamps for Echoes saved to your personal list.

We request birth year and month to determine eligibility. In your private account record, we keep your age bracket and the dates you become eligible for access at 16 and 18, derived from the declared year and month. Those dates can indirectly reveal the declared year and month. We do not request a birth day or separately retain the entered year and month.

03

How location works

Location is used to show the map, attach an Echo to a place, find nearby Echoes, or check an on-site unlock. Map, Echo creation, and on-site opening checks begin while you use the relevant feature in the foreground. If you separately enable nearby Echo arrival alerts, the app may use high-accuracy movement location updates and operating-system region events in the background with device permission. It requests updates around 250 metres of movement to refresh nearby regions, but the operating system may defer or stop them. An on-site unlock sends a fresh location fix for spoofing, accuracy, distance, and speed checks; the latest verification fix may remain in a private account record.

If you separately opt in to venue leadership, you manually start a check-in while the app is in the foreground for a fresh server-resolved Google Place selection. The server checks whether your fresh phone location fix is within 150 metres of that venue plus the reported accuracy allowance, accepting only fixes with accuracy of 35 metres or better. Raw phone coordinates are not stored for leadership. The selected Google Place coordinates are temporary and valid for no more than 15 minutes. At most one visit day counts per venue per UTC day.

The location of an Echo you create may be shown on the map to people allowed to see that Echo. Optional local participation stores an approximate zone and day, rather than a precise coordinate history. The app does not infer passive location from Wi-Fi names/BSSIDs or apartment numbers.

04

Nearby alerts and personal reopening

If you separately enable nearby Echo arrival alerts, we may ask for notification and background location/region permissions on your device. The app refreshes at most 20 nearby Echo regions using background movement location updates, and the operating system monitors region-entry events; region metadata for currently visible Echo candidates is held in secure device storage for the active account and session, treated as stale after 15 minutes, and refreshed before reuse. The device list is cleared when you turn the preference off or sign out. This is not a continuous location history. A fresh phone location fix may be sent to the server to recheck whether a candidate Echo remains eligible and visible while refreshing regions after movement or handling a region-entry event; the arrival-alert path does not store those raw phone coordinates. A separate private account record may hold the latest fix used for an on-site Echo opening, as explained above.

To limit repeat alerts, a private account record keeps an Echo ID and the last alert UTC day, capped at 200 entries; records outside a rolling 30-UTC-day window are pruned on new activity and by about-hourly cleanup, which can lag. Push text is generic and includes no Echo content or location. You may turn off the preference and revoke device permissions; the operating system may delay or omit background events.

If you save an Echo to your personal list, you may choose default, permanent, hourly, daily, weekly, monthly, or yearly reopening. The server stores that choice and saved/opened timestamps in your private Echo unlock record. Every personal reopening outside the default mode requires returning to the Echo location and supplying a fresh fix, even if that Echo was originally openable from anywhere. A personal preference cannot extend the creator’s Echo lifetime or override audience, block, or deletion rules.

05

Venue leadership

Visit days in the most recent 90 UTC days determine the ranking. Leadership requires at least two distinct visit days. The current leader changes only when another person has more visit days; the incumbent remains on a tie. While you lead, your username may be shown as the venue leader, subject to blocking rules. This in-app ranking gives no ownership, operating right, or other legal right over the venue.

06

Purposes and recipients

We use data to verify accounts, host content and show it to your chosen audience, apply place and time conditions, deliver notifications, review abuse reports, provide support, and keep the service secure.

Other users may see the profile fields and content allowed by your visibility choices. Authorized moderators may review reports, uncertain content, and appeals; new Echoes without the automated-check choice wait for human review. We use Google Firebase/Google Cloud for infrastructure, Google Maps/Places for maps and place search, and the Apple or Google sign-in provider you choose. See Firebase privacy information and the Google Privacy Policy for more information.

07

Optional automated Echo screening

When this feature is enabled, we send Echo text and media to the OpenAI API for safety screening only if you give separate, explicit consent while creating a new Echo or for your own Echo still awaiting human review. OpenAI moderation checks text and images; an additional vision model may check text in images and context. Audio is transcribed by OpenAI and screened. About two frames per second are sampled from video and its audio is transcribed and screened. Sampling does not cover every video frame, and automated screening cannot guarantee detection of every violation.

We do not add your user ID, phone number, or phone-location coordinates as separate fields in OpenAI requests, though the content itself may contain such information. Without that explicit choice, we do not send that Echo to OpenAI for automated screening and it remains in the existing human-review path. If automated screening is unavailable, the Echo remains in human review. Errors or uncertain results keep content unpublished for human review.

OpenAI states that API data is not used to train its models unless the customer separately opts in. OpenAI processing may occur in countries outside our Firestore data region. Safety-data retention, periods, and image exceptions vary by endpoint; see the OpenAI data controls. Echo content rejected or hidden through automated screening remains inaccessible during the 30-day period for requesting one human review. If you do not appeal within that period, scheduled deletion may start. A timely appealed Echo is not purged by that cleanup while it awaits a human decision. If you request account deletion sooner, the account-deletion process applies. We process decision categories, appeal state, and minimal audit records for safety and support.

08

Retention and deletion

Account data is kept while your account is active and for as long as needed to provide a feature. A Google Place selection for an Echo or venue leadership is valid for 15 minutes. Expired selections are removed by a cleanup job that runs about every 15 minutes; processing can lag briefly. A selection is also removed when replaced, used to create an Echo, or during account deletion. Unfinished Echo uploads are scanned for cleanup after about 24 hours, and optional local presence day records are marked to expire after about 366 days. Opted-in venue leadership visit-day records are used for a rolling 90-day window and cleaned up by scheduled jobs as they expire. Nearby-arrival alert records are capped at 200 entries containing an Echo ID and UTC day; records outside a rolling 30-UTC-day window are pruned on new activity and by about-hourly cleanup, so physical deletion can lag. Personal reopening choices and timestamps remain in your private unlock record until you remove the Echo from your personal list or delete your account. Withdrawing nearby-alert consent stops new monitoring and starts cleanup of feature records. Scheduled cleanup means the exact deletion time depends on processing.

Withdrawing venue leadership consent starts a retryable process to erase your visit records; you cannot re-enable the feature until cleanup finishes. When you request account deletion, access to your session closes immediately. Profile data, Echoes, media, historical message records, and account-linked records are then erased in the background. A minimal, de-identified audit record of a report category and moderation outcome may remain. Copies or screenshots already taken by others are outside our control. Read the account deletion instructions.

09

Your choices and requests

In the app, you can edit your profile, Echo audience, blocking and notification preferences, and delete your own Echoes or account. You can separately enable or disable nearby Echo arrival alerts, manage saved Echoes and reopening choices, and change location and notification permissions in device settings. For access, correction, deletion, or other rights that may apply under local law, email privacy@echoks.com. We may need to verify your connection to the account; do not send your password or SMS code.

10

Age and security

You must be at least 16 to create an echOKs account. Some features are limited to users aged 18 or older. We use server-side checks, a single active device session, authorized content unlock records, and abuse review to protect access. No security measure offers absolute protection.

11

Processing locations and changes

Our Firestore database is configured in a European multi-region. Firebase Authentication processes authentication data in the United States; other provider processing may occur in other countries. We may update this policy when the app or data practices change and will communicate material changes through appropriate channels.

12

Optional translation and place summaries

Separate from content safety screening, you can choose to send an Echo text you are authorized to open to OpenAI for translation, with an explicit choice for each action. Place summaries use at most 10 texts currently accessible to you at that place. Hidden and sealed content is excluded. The target language and text are transferred; unnecessary account, phone and raw GPS data are not. Results are scoped to the user and content revision, retained for 24 hours and cleared on consent withdrawal or source deletion. AI translations and summaries may be inaccurate.

13

Optional contact matching

Address-book access is requested only after you choose this feature and grant permission. Raw numbers and contact names are not uploaded. Your device hashes international phone numbers with a one-use random challenge valid for 5 minutes. Up to 200 hashes per day are sent to the server and matched in memory only against members with verified phones who enabled discoverability. Hashes are not retained; the challenge is removed on use or by cleanup after expiry. This is not a formal cryptographic private-set-intersection protocol. Discoverability is off by default and can be withdrawn. Member-to-member private messaging is not offered.

14

Optional AR and building floors

AR starts only with your camera and precise-location permission. Google ARCore Geospatial may process camera images and device location through Google to localize the scene. echOKs does not retain raw AR camera frames; a spatial anchor you choose for a shared Echo stores its position, orientation and content revision. Map and two-dimensional photo alignment are available when device support or localization quality is insufficient. Meter-level and floor accuracy are not guaranteed.

SuperEcho checks a registered real building boundary against a current GPS fix. Device floor and pressure signals can help estimate floor changes; you confirm the floor you are actually on. Private, session-bound floor confirmation lasts 2 minutes and pressure calibration 30 minutes. Reconfirmation is required after changing floors or expiry. Raw GPS and Wi-Fi identifiers from these checks are not retained as a history. A floor-restricted Echo stores its building ID and floor as an access rule.

15

Charmecho

Charmecho is optional and available only to verified members aged 18 or over. A location sample establishes the zone; zone identifiers and short-lived session presence are stored instead of raw coordinates. Votes, bounded interactions, account trust and confirmed moderation outcomes contribute to rankings over 90 days. A server-side keyed phone hash limits repeated influence from the same phone. Rankings are withheld without enough participants, and a leader can hide their identity. You choose whether to display your username, score and ring in the local ranking.

Free daily virtual Charm balances and 5/10-unit gifts have no monetary value. Purchasing, cash redemption and use as a payment method are not offered. Ring privileges may temporarily highlight a profile or Echo. A public Echo temporarily hidden by a local leader for a bounded safety reason is referred to an authorized moderator; leadership confers no property or permanent deletion right. Withdrawal starts retryable cleanup of participation records; minimal de-identified moderation audit records may remain.

16

Echochain

Enrolling a photo in Echochain is a separate optional action. Derived photo-similarity fingerprints and chronological links you confirm are retained for up to 365 days. Suggestions use only photos you are authorized to access and never create links automatically. Two-dimensional alignment is a comparison aid, not proof of the same place or event. Derived data and links are cleared after editing, hiding, deletion or withdrawal.