Privacy policy

What happens to your data

EchoScribe is built around local control. The app can process recordings, shared audio, pasted text, URLs, prompts, transcripts, summaries, translations, generated images, TTS audio, local history, settings, API keys, and optional debug logs, but EchoScribe does not collect those contents on an EchoScribe server. They remain on your device unless you explicitly start a provider request, share an output, export/save a file, or use the public website.

No EchoScribe backend for AI data

There are no EchoScribe servers that receive, store, review, train on, or forward your recordings, prompts, API keys, transcripts, summaries, translations, generated images, or TTS text/audio. The public website only serves the static landing page; it is not an AI request backend.

Direct provider requests

When you choose OpenAI, Google Gemini, Anthropic Claude, xAI Grok, or ElevenLabs, EchoScribe sends the required request directly from your device to that provider's API. When you choose Local AI, supported text and transcription requests go to the endpoint you configured. On iPhone, before the first content transfer to each provider, the app shows the destination, data type and purpose and asks for explicit permission. You can withdraw that permission in Settings to block future transfers. Withdrawal cannot recall content already sent.

Content sent for the feature you request

  • Audio is used for recording, transcription, summaries, and optional dictation workflows. Imported audio is sent as a file; an MP4 container may include video tracks that are sent with it. Import an audio-only file if you do not want to send those tracks.
  • Text, shared messages, extracted webpage text, and custom prompts are used for summaries, translation, and re-processing.
  • Image prompts are used to generate images through the selected image provider.
  • TTS text is used to generate playable audio through the selected speech provider.

Local storage and deletion

API keys are stored locally using platform secure storage: Android Keystore on Android and Keychain on iPhone. iPhone provider-sharing choices are stored locally on the device. History, transcripts, summaries, generated media, cached TTS audio, settings, and debug information are stored locally on your device so you can reuse them. You can delete history, clear app data and remove API keys in the app settings. Uninstalling removes the app’s local files, but iPhone Keychain items may remain; remove your API keys before uninstalling. Provider-side retention must be managed in the account or dashboard of the provider you used.

Recipients and third parties

EchoScribe does not sell data, use ad networks, embed tracking SDKs, or share app content with data brokers. AI content is disclosed only to the provider you selected for the action you started. Those providers process the request under their own terms, privacy policies, abuse monitoring, retention rules, and billing settings. EchoScribe cannot delete or change provider-side logs after a direct API call has been made.

Provider retention and model-improvement rules vary by API, account, region and account settings. For example, ElevenLabs may use submitted data to improve its models unless you opt out or have an applicable enterprise arrangement. Gemini unpaid-service rules can allow model improvement and human review, with different rules for paid services and users in the EEA, Switzerland and the UK. Withdrawing permission in EchoScribe blocks future app requests; it does not change these provider settings or delete previously sent content.

Review the applicable API terms before sending confidential content: OpenAI data controls, Gemini API terms, Anthropic API terms, xAI API security and ElevenLabs data-use settings. For Local AI, the operator of your configured endpoint determines its retention and processing rules.

Permissions and platform features

Microphone access is used only when you record. The iPhone version stops recording when the app goes into the background and does not request background audio access. The iPhone Share Extension uses an App Group to pass shared text, URLs and audio to the app. Files are accessed only when you import, share or export them. The optional Android Floating Dictation feature uses Accessibility only to detect editable fields, show the floating microphone, and insert text after your approval. Password, PIN, payment, banking, credit-card, and phone fields are blocked.

Website and technical access logs

Visiting the EchoScribe website creates normal technical webserver and Cloudflare delivery/security data, such as IP address, timestamp, requested URL, user agent, TLS/security metadata, and error status. These logs are used for secure delivery, troubleshooting, abuse prevention, and server operation. Current nginx logs rotate daily and are kept for up to 14 rotations. Website logs do not contain your EchoScribe API keys or AI request contents.

Your controls and rights

You decide which provider receives a request, which API key is used, whether Pro mode is enabled, whether history/debug logging is kept locally, and when local data is deleted. On iPhone you can withdraw each provider permission in Settings. Opening a URL or extracting webpage text also contacts the website hosting that URL, independently of any AI provider request. Where data protection law such as the GDPR applies, you may request access, correction, deletion, restriction, portability, or objection regarding data controlled by the EchoScribe project. For data processed by OpenAI, Google, Anthropic, xAI, or ElevenLabs through their API, please contact that provider directly. For EchoScribe project and privacy questions, contact app@wean.de.

Optional tutorial videos

All tutorial videos and captions are served directly from this website after you select a play button. These media requests use the same website delivery services and technical access logs described above. Closing the player stops playback and cancels its media load.