Privacy Policy

Published July 28, 2026 · Effective August 11, 2026

Replaces the separate app policy (6 July 2026) and website policy (25 April 2026).

1. Scope

This policy explains how HushedEchoes (“we”, “us”) collects, uses, shares and retains information across everything we run: the mobile app for Android and iOS, hushedechoes.com and its subdomains, community features, meditation and audio, breathing and mind games, Umbrellas (private circles), chats and direct messages (together, the “Services”).

It replaces the two separate policies we used to publish for the app and the website. Where a feature exists on only one platform, we say so.

We operate from India and follow India’s Digital Personal Data Protection Act, 2023 (DPDPA) and the DPDP Rules, 2025. If you are in the EEA or the UK, the GDPR applies to our processing and this policy is written to meet it.

2. What we collect

Things you give us.

  • Account — email address, and if you use them, a display name or pseudonym, Google or Apple sign-in identifiers, and preferences. The app works without an account in offline-only mode; sync and sharing need one.
  • Content — voice recordings and transcripts, typed day-logs and notes, tasks and reminders, mood entries and reflections, images and files, messages in Umbrella chats and DMs, and anything you post to a circle or the public community.
  • Health and well-being information — what you record may describe your mood, mental state, symptoms or treatment. Where that counts as sensitive personal data or special category data, we process it on the basis in section 7.
  • Payments — if you send a voluntary gift, our payment providers handle it (one for Indian Rupees, one for other currencies). We get confirmations, amounts, currency, status and limited billing metadata. We never see full card numbers.
  • Correspondence — support requests, feedback, bug reports.

Things collected automatically.

  • Device model, OS and version, app version, language, time zone, device and installation identifiers, network type, crash and diagnostic data.
  • Usage — features accessed, screens viewed, session frequency and duration, notification interactions, performance and errors. We use third-party analytics and crash-reporting providers in the app and on the website.
  • Approximate location — country or region, inferred from your IP. On the website it picks a sensible gift currency. We do not collect GPS location.
  • Push notification tokens, if you enable notifications.
  • Cookies on the website, for authentication, security, preferences and analytics. Where the law requires it, we ask before setting non-essential cookies.

What we do not collect.

Not your contacts, not your precise location, not data from other apps on your device. We show no third-party advertising, and we do not sell personal data.

3. How we use it

  • To run the Services — accounts, sync, messaging, gifts.
  • To transcribe and organise what you record, and derive tasks, reminders, moods and summaries from it (see section 4).
  • To personalise your own experience — your trends, your predictions, your prompts.
  • To fix problems, evaluate features and measure performance.
  • To develop and improve automated systems. Training our own models on your content is optional and off unless you switch it on — see section 4.3.
  • For analytics and product decisions.
  • For safety and security — fraud, abuse, harassment, security incidents, breaches of our Terms.
  • To talk to you — service messages, security alerts, policy changes, replies, and product updates unless you opt out.
  • To comply with law, and to establish, exercise or defend legal claims.
  • For business operations, including a merger, acquisition, financing or sale of assets.

We may combine information across platforms for these purposes, and may produce aggregated or de-identified information that does not identify you, which we may use and share for any purpose.

4. Automated processing, AI and machine learning

This is the section that matters most, so we have written it to be read rather than skimmed.

4.1 What leaves your device, and to whom

Transcription, sorting your words into tasks and moods, summaries and assistant replies run on third-party cloud infrastructure, not on your device. When you use those features, the relevant content is sent to those providers.

Which provider handles a request depends on the feature, the language, and available capacity. The categories of recipient — what each receives, why, and where — are at hushedechoes.com/legal/subprocessors. If you want the names of the specific companies, email hello@hushedechoes.com and we will tell you.

Before content is sent, we strip your name, email address and internal user ID from the request. We cannot promise the content itself is anonymous. If you say your own name, someone else’s name, or an address in a recording, those words go with it.

4.2 Whether providers may use your content for their own purposes

Except as stated below, these providers act on our instructions under contracts that limit their use of your information to the services they provide to us. They are not permitted to use your content to develop or train their own models.

One exception, which we name because you need to know it.

Transcripts of what you record, and the text of what you type into a day-log, are sent to Google’s Gemini API to be sorted into tasks, moods and reminders. Google’s terms for the tier we use permit Google to use the content submitted and the responses generated to provide, improve and develop Google products and services, and permit human reviewers to read, annotate and process that content. Google states it disconnects such content from your account and our API key before human review. Google’s terms for this tier also advise against submitting sensitive or personal information to it.

We have chosen to use that tier, and we are telling you plainly because it should change what you decide to put in:

Treat anything you record or write in a day-log as something a person at Google may read, and as something that may inform Google’s own model development.

If that is not acceptable to you, read 4.4 below — it sets out exactly what declining does and does not do today.

One provider is unconfirmed.

For Hindi and Hinglish speech we use a provider whose data-use position we have not been able to verify from its published terms, and we are seeking written confirmation. Until we have it, assume that provider’s own terms govern what it does with what it receives.

Where a provider may retain or learn from what it receives, that content lives under the provider’s retention practices, not ours.

4.3 Training our own models is optional, and off by default

Separately from the providers above, we may use content to improve our own prediction models — the ones behind trends and suggestions across accounts.

This needs your explicit opt-in. It is off by default, shown as a distinct unticked choice, and declining it disables nothing. Personalisation inside your own account is core functionality and is not governed by this setting. Change it any time in the app under Me → How your data works. We record when you decided.

End-to-end encrypted chats and DMs are never included, whatever the setting, because we cannot read them.

Switching it off stops all future use immediately. It cannot undo training already done — a model that has learned from a dataset cannot unlearn one contribution to it. We would rather say that than imply otherwise.

4.4 What declining does, and does not, do today

We would rather describe this accurately than make it sound tidier than it is.

  • Declining the AI notice turns off voice recording. Recording, transcription and the assistant cannot run without this processing. Everything else — writing, moods, tasks, meditation, breathing, community, Umbrellas — keeps working.
  • Typed day-log entries are processed the same way, whether or not you use voice, so they can be sorted into tasks, moods and reminders. Sorting is not separately switchable from transcription today.
  • There is no way to use the day-log features while excluding this processing. If that matters to you, the reliable control is what you choose to put in.
  • Content processed this way is not end-to-end encrypted (section 9). Your Umbrella chats and DMs are, and are never sent for this processing.
  • Where the law needs your consent, we ask, and you can withdraw it (section 10).
  • None of this produces legal or similarly significant effects. We do not use it to decide eligibility for services, credit, employment or insurance.

4.5 Accuracy

Transcription, classification and assistant output is generated automatically and may be wrong, incomplete or unsuitable. It is not a clinical assessment. Do not treat it as a record of fact or as health advice.

5. Who receives your information

We do not sell personal data. The categories of recipient are below; the fuller version, including how providers may use your content, is at /legal/subprocessors.

CategoryWhat it receivesPurposeLocation
Database, file storage and authenticationAccount data, synced content, uploaded filesStoring and syncing your account and contentIndia
Website hostingWebsite requests, IP address, approximate countryServing the websiteUnited States and a global edge network
Speech-to-text and language processingVoice recordings; transcriptsTranscription; sorting into tasks, moods and reminders; assistant repliesUnited States and India
Text-to-speechAssistant reply textProducing spoken assistant repliesIndia and a global edge network
Analytics, crash reporting and push notificationsDevice and installation identifiers; usage events; crash data; notification tokensUnderstanding how the Services are used; diagnosing faults; delivering notificationsUnited States and the European Union
Sign-in providersSign-in identifiersAuthentication, where you choose to sign in with a third-party accountUnited States
PaymentsTransaction and billing metadataProcessing voluntary gifts, if you choose to send oneIndia, United States and the European Union
EmailReported community content and report metadata; service email contentDelivering moderation alerts and service emailUnited States

Not every provider receives every request. If you want the names of the specific companies in any category, email hello@hushedechoes.com and we will tell you.

Beyond those recipients, information may be shared:

  • With other users — whatever you choose to share, with the circle or community you share it into. Think before you post.
  • As aggregated or de-identified data that does not identify you, for any purpose.
  • For legal, safety and enforcement reasons — to comply with law or legal process, respond to a lawful request, enforce our Terms, prevent fraud or abuse, or protect people.
  • In a corporate transaction — a merger, acquisition, financing, reorganisation, insolvency or sale, subject to this policy or a successor.
  • When you tell us to.

6. Where your data lives, and crosses borders

Account data is stored in our primary database, hosted in India. Content sent to automated features is processed in the United States, in India, or across a global edge network. Analytics, crash reporting, push, authentication, hosting, email and payment providers may process information in the United States, the EU and elsewhere.

If you are in the EEA or the UK, your personal data is processed outside the EEA and the UK — including its storage in India. Neither India nor the United States has a European Commission adequacy decision of general application, so these are restricted transfers requiring a safeguard under Chapter V of the GDPR. Our website analytics provider is EU-hosted and is not a restricted transfer.

For each recipient outside the EEA/UK we rely on an appropriate safeguard: the European Commission’s Standard Contractual Clauses, with the UK International Data Transfer Addendum where the transfer is from the UK; the EU–US Data Privacy Framework where the recipient is certified; or another Chapter V mechanism. We assess each transfer and apply supplementary measures where the assessment calls for them.

Ask which mechanism applies to a particular recipient at hello@hushedechoes.com.

7. Legal bases and grounds

EEA/UK (GDPR). We rely on:

  • Contract — to provide the Services you asked for.
  • Consent — for health-related and other special category data, for training our own models on your content, for non-essential cookies, for optional communications, and wherever else the law requires it. Withdraw any time. For special category data we rely on explicit consent under Article 9(2)(a).
  • Legitimate interests — security and abuse prevention, analytics and product improvement, internal research, business operations, and legal claims, where not overridden by your rights.
  • Legal obligation and, rarely, vital interests where life or safety is at risk.

India (DPDPA).

We process on the basis of your consent, given through the notice shown to you and this policy, and on the legitimate uses the DPDPA permits — including compliance with law and responding to a medical emergency or threat to life or safety.

8. How long we keep things

CategoryRetention
Data only on your deviceUntil you delete it or uninstall the app
Synced voice recordingsNormally removed around 14 days after capture; the transcript is the lasting record. Removal runs as a rolling sweep during ordinary use, so exact timing varies and we do not guarantee deletion on a fixed date.
Assistant audioDiscarded after transcription; a retry record may persist up to 24 hours
Assistant conversation contextCompact recent history and source references, up to 12 hours, so follow-up questions stay connected
Synced content (logs, transcripts, moods, tasks, messages)Until you delete it or delete your account, plus up to 30 days for backups to roll over
Account and billing recordsAs long as tax, accounting and legal obligations require
Content held by third-party providersUnder the provider's own retention practices — see section 4.2. Content sent to the sorting provider described there is retained under that provider's practices, not ours, and deleting your copy does not retract it
Aggregated and de-identified informationMay be kept indefinitely
Diagnostics and analyticsAggregated or pseudonymised, per provider defaults

Content already used to train a model cannot generally be withdrawn from it. Deleting your content stops future use; it does not reverse training already done.

9. Security, and the limits of encryption

We use measures appropriate to the risk: encryption in transit, encryption at rest, row-level access controls, and secure storage of credentials on your device.

End-to-end encryption.

Umbrella chats and direct messages, including voice notes sent in chat, are end-to-end encrypted using X25519 key exchange and XChaCha20-Poly1305 (via libsodium). Keys are generated and held on your device; our servers relay ciphertext they cannot read. Circle keys rotate when a member is removed.

The limits, stated plainly.

End-to-end encryption covers chats and DMs only. Voice day-logs, transcripts, moods, tasks and community posts are encrypted in transit and access-controlled, but are not end-to-end encrypted — the automated features in section 4 cannot operate on content we cannot read. Routing metadata (who talks to whom, and when) stays visible to us. A conversation only becomes encrypted once every participant is on a supporting app version. Because keys never leave your device, we cannot recover encrypted messages if you lose it or reinstall.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

10. Your rights and controls

  • Access — ask for a copy of what we hold about you.
  • Correct — fix inaccurate data, or edit it in the app.
  • Delete — individual logs, messages and tasks in the app, or your whole account from settings. Account deletion removes stored files as well as database rows. Deletion cannot reach content already sent to a third-party provider — we can stop sending, but we cannot retract what has been transmitted, and content already used to develop a model cannot be withdrawn from it. See sections 4.2 and 8.
  • Withdraw consent — including the model-training opt-in in section 4.3. It does not affect processing already carried out, and may make some features unavailable.
  • Object or restrict — where processing rests on legitimate interests, in the circumstances the law provides.
  • Portability — receive certain data in a structured, machine-readable format.
  • Nominate — nominate someone to exercise your rights on death or incapacity, as the DPDPA provides.
  • Complain — to the Data Protection Board of India, or your local supervisory authority in the EEA/UK.

Use the controls in the app or email hello@hushedechoes.com. We acknowledge within 48 hours and respond within 30 days, or sooner where the law requires. We may need to verify your identity first.

You can also turn notifications off, revoke microphone and calendar permissions, use the app without an account, change the model-training opt-in at any time, and choose what you share.

11. Children

The Services are for adults 18 and over. We do not knowingly collect data from anyone under 18. If you believe a minor is using the Services, tell us and we will delete the account and its data.

12. This is a wellness service, not a medical one

HushedEchoes is not a medical service, not a substitute for professional care, and not an emergency or crisis service. Anything in the app, including generated summaries and insights, is not a diagnosis or clinical advice. If you are in crisis or considering self-harm, contact a qualified professional or your local emergency services immediately. See our disclaimer and crisis resources.

13. Changes to this policy

We may update this policy. For material changes we will tell you in the app and, for signed-in users, by email, at least 14 days before the change takes effect. Where a change needs your consent, we will get it before applying the change to your data. The current version always lives at hushedechoes.com/privacy.

14. Contact, grievance officer and representatives

General and privacy enquiries: hello@hushedechoes.com

Grievance Officer (DPDPA and IT Rules)

Harshal Goyal

Email: hello@hushedechoes.com — subject line Grievance

We acknowledge grievances within 48 hours and resolve within 30 days. If you are unsatisfied, you may escalate to the Data Protection Board of India. The Grievance Officer is also the person who answers questions about our processing for the purposes of Rule 9 of the DPDP Rules, 2025.

Data Protection Officer

Jigar Vaishnav

Email: hello@hushedechoes.com — subject line Data Protection

EU and UK representatives (GDPR Article 27).

Because we are established outside the European Union and offer the Services to people in the EEA and the UK, we appoint representatives who may be contacted on all matters relating to our processing:

  • EU representative: Jigar Vaishnav.
  • UK representative: to be appointed before UK launch.

You may contact your local supervisory authority, or the Data Protection Board of India, at any time.