Privacy Policy
Last updated: 17 November 2025
EchoNest (“we”, “our”, or “us”) is a product owned and operated by SiteGrowth Company Ltd, a company registered in England & Wales (Company No: 16742174), with its registered office at 315 Uppingham Road, Leicester, LE5 4DN, United Kingdom.
We are committed to protecting your privacy and handling your data safely, securely, and transparently. This Privacy Policy explains how we collect, use, store, and protect your information when you use our website, mobile app, and AI-powered therapy services.
1. Information We Collect
a) Personal Information You Provide
- Name, email address, and account details when you register.
- Subscription and payment details (processed securely by Stripe — we do not store card numbers).
- Optional demographic information such as age, gender, and country to personalize your therapy experience.
b) Therapy & Usage Data
- Text, voice, and chat interactions with the EchoNest AI therapist.
- Journaling entries, mood scores, daily check-ins, guided session data.
- Session timestamps and credit usage.
d) Free Trial Eligibility Data
To prevent abuse of free trial offers, we collect and store the following:
- Your email address
- The date when free trial credits were issued
This allows us to ensure that each user can only receive the free trial once within a 1-year period.
2. How We Use Your Information
We use your data to:
- Deliver AI-powered therapy sessions (text + voice).
- Provide journaling, mood tracking, and personalised wellbeing insights.
- Improve the accuracy and safety of our AI models using anonymised, aggregated data.
- Process payments and manage subscriptions.
- Maintain platform security and detect abuse.
- Communicate updates, service notifications, and customer support responses.
Your data is never sold.
3. Legal Basis for Processing (UK & EU GDPR)
For users in the UK or EU, we process your information under:
- Consent (when you sign up or opt in).
- Contract (to provide the service you subscribe to).
- Legitimate Interests (security, performance, service improvement).
- Legal Obligations (financial record retention, safety requirements).
4. Data Storage & Security
We take strict measures to protect your data:
- Encryption in transit (HTTPS/TLS) and at rest.
- Secure cloud infrastructure (AWS, Azure, or equivalent).
- Role-based access controls for authorised personnel only.
- No advertising networks access any therapy content.
Messaging, journals, and therapy logs are private and never shared with third parties without your consent.
5. Sharing of Data
We may share limited data with:
- Stripe — for payment processing.
- Resend — to deliver transactional emails (e.g., login codes, updates).
- Glitchtip or similar error monitoring tools — for debugging and stability.
- Cloud hosting providers (e.g., AWS, Vercel) — to operate our infrastructure.
- Legal authorities when required by law or safety concerns.
We do not share therapy conversations, voice logs, or journals for advertising or commercial resale.
6. Your Rights (DSAR)
You have the right to:
- Access your personal data
- Rectify inaccurate or incomplete data
- Delete your data (“Right to be forgotten”)
- Export your data (data portability)
- Object to certain processing activities
- Withdraw consent at any time
To exercise these rights, email: support@echonest.co.uk
7. Children’s Privacy
EchoNest is designed for adults and is not for individuals under 18.
We do not knowingly collect or store data from minors.
8. Data Retention
We keep your data only as long as needed to provide the service or comply with laws.
Retention Timeline
- User Accounts: Retained while active → deleted within 30 days after account deletion.
- Chat Messages & Conversations: Retained for 12 months unless manually deleted earlier.
- Mood Tracking & Journals: Retained for 6 months.
- Authentication Tokens: Retained for 30 days after expiration.
- Usage Logs: Retained for 12 months.
- Billing & Transaction Records: Retained for 7 years (legal requirement).
- Voice Recordings: Retained for 12 months unless voice logging is disabled.
Third-party data (e.g., Stripe) is retained according to their policies.
9. Account Deletion
You can delete your account anytime from Account Settings.
When deleted:
- Chats, journals, mood logs, and personal data are permanently deleted within 30 days.
- Financial records remain anonymised but retained for 7 years (required by UK law).
- Access to the platform is removed immediately.
10. International Data Transfers
Your data may be processed or stored outside your home country.
We ensure all transfers comply with legal safeguards including:
- Standard Contractual Clauses (SCCs)
- Vendor compliance (ISO/SOC certifications)
- UK GDPR-approved transfer mechanisms
11. Cookies & Tracking
We use cookies to:
- Maintain secure login sessions
- Improve website performance
- Analyse usage
- Save your preferences
You can manage cookies in your browser settings.
12. Changes to This Privacy Policy
We may update this policy occasionally to reflect product or legal changes.
Updates will be posted on this page with a revised date.
13. Contact Us
For questions about privacy or data use: support@echonest.co.uk