Privacy Policy

Published July 28, 2026 · Effective August 11, 2026 · Updated August 13, 2026

Replaces the separate app policy (6 July 2026) and website policy (25 April 2026).

1. Scope

This policy explains how HushedEchoes (“we”, “us”) collects, uses, shares and retains information across everything we run: the mobile app for Android and iOS, hushedechoes.com and its subdomains, community features, meditation and audio, breathing and mind games, Umbrellas (private circles), chats and direct messages (together, the “Services”).

It replaces the two separate policies we used to publish for the app and the website. Where a feature exists on only one platform, we say so.

We operate from India and follow India’s Digital Personal Data Protection Act, 2023 (DPDPA) and the DPDP Rules, 2025. If you are in the EEA or the UK, the GDPR applies to our processing and this policy is written to meet it.

2. What we collect

Things you give us.

  • Account — email address, a display name or pseudonym, Google or Apple sign-in identifiers, and preferences. The mobile app requires a signed-in account and a current 18+ verification result. Public website pages can be read without an account; account features and posting require sign-in. Public posts show your board name, not your account name or email, while we retain the account link for safety, moderation and deletion.
  • Age check— the mobile app asks Google Play or Apple for a privacy-preserving age range where available. Otherwise, you enter a birth date for a one-time 18+ threshold check. The app and mobile backend retain the adult verdict, not that exact birth date. The website’s separate signup flow currently retains the birth date supplied there until account deletion.
  • Content — voice recordings and transcripts, typed day-logs and notes, tasks and reminders, mood entries and reflections, images and files, messages in Umbrella chats and DMs, and anything you post to a circle or the public community.
  • Health and well-being information — what you record may describe your mood, mental state, symptoms or treatment. Where that counts as sensitive personal data or special category data, we process it on the basis in section 7.
  • Payments — if you send a voluntary gift, our payment providers handle it (one for Indian Rupees, one for other currencies). We get confirmations, amounts, currency, status and limited billing metadata. We never see full card numbers.
  • Correspondence — support requests, feedback, bug reports.

Things collected automatically.

  • Device model, OS and version, app version, language, time zone, device and installation identifiers, network type, crash and diagnostic data.
  • Usage — features accessed, screens viewed, session frequency and duration, notification interactions, performance and errors. Website page views and feature usage go to PostHog EU Cloud. Signed-out events carry no HushedEchoes account ID; after sign-in, we send only the internal account ID, never your email address or account role.
  • Approximate location — country or region, inferred from your IP. On the website it picks a sensible gift currency. We do not collect GPS location.
  • Push notification tokens, if you enable notifications.
  • Cookies on the website, for authentication, security, preferences and analytics. Where the law requires it, we ask before setting non-essential cookies.

What we do not collect.

Not your contacts, not your precise location, not data from other apps on your device. We show no third-party advertising inside the app, and we do not sell personal data. When we advertise HushedEchoes on Instagram or Facebook, the app tells Meta only that it was opened and that an account was created, so we can tell whether an ad led to an install; we do not collect the advertising identifier, and no content ever goes to Meta.

3. How we use it

  • To run the Services — accounts, sync, messaging, gifts.
  • To transcribe and organise what you record, and derive tasks, reminders, moods and summaries from it (see section 4).
  • To personalise your own experience — your trends, your predictions, your prompts.
  • To fix problems, evaluate features and measure performance.
  • To develop and improve automated systems. Training our own models on your content is optional and off unless you switch it on — see section 4.3.
  • For analytics and product decisions.
  • For safety and security — fraud, abuse, harassment, security incidents, breaches of our Terms.
  • To talk to you — service messages, security alerts, policy changes, replies, and product updates unless you opt out.
  • To comply with law, and to establish, exercise or defend legal claims.
  • For business operations, including a merger, acquisition, financing or sale of assets.

We may combine information across platforms for these purposes, and may produce aggregated or de-identified information that does not identify you, which we may use and share for any purpose.

4. Automated processing, AI and machine learning

This is the section that matters most, so we have written it to be read rather than skimmed.

4.1 What leaves your device, and to whom

Transcription, sorting your words into tasks and moods, summaries and assistant replies run on third-party cloud infrastructure, not on your device. When you use those features, the relevant content is sent to those providers.

  • Sarvam AI — receives each day-log recording first for speech-to-text and receives transcripts to identify tasks, moods and reminders. For Assistant, Sarvam receives your question, recent compact conversation turns and the relevant excerpts needed to answer. It also receives the final reply text when you request spoken audio.
  • Groq — is the fallback when Sarvam is unavailable or cannot transcribe a recording or answer an Assistant turn. It receives the audio, or the Assistant question and the same limited context needed for that answer. Groq does not classify day-log transcripts or produce spoken reply audio.

The complete recipient list and processing locations are at hushedechoes.com/legal/subprocessors.

Before content is sent, we strip your name, email address and internal user ID from the request. We cannot promise the content itself is anonymous. If you say your own name, someone else’s name, or an address in a recording, those words go with it.

4.2 Provider training and retention

Provider model training is disabled on the Sarvam and Groq accounts used for HushedEchoes. Training being disabled does not by itself mean that a provider stores nothing.

Our Groq project is configured for zero retention of customer content. Groq may still retain non-content operational metadata, such as request volume and service performance. Sarvam’s published standard policy permits request-content retention for up to 30 days after last access and usage-log retention for up to one year unless a separate agreement or deletion request shortens those periods. We therefore do not describe Sarvam as zero-retention.

4.3 Training our own models is optional, and off by default

Separately from the providers above, we may use content to improve our own prediction models — the ones behind trends and suggestions across accounts.

This needs your explicit opt-in. It is off by default, shown as a distinct unticked choice, and declining it disables nothing. Personalisation inside your own account is core functionality and is not governed by this setting. Change it any time in the app under Me → How your data works. We record when you decided.

End-to-end encrypted chats and DMs are never included, whatever the setting, because we cannot read them.

Switching it off stops all future use immediately. It cannot undo training already done — a model that has learned from a dataset cannot unlearn one contribution to it. We would rather say that than imply otherwise.

4.4 What declining does, and does not, do today

We would rather describe this accurately than make it sound tidier than it is.

  • Declining the AI notice turns off voice recording. Recording, transcription and the assistant cannot run without this processing. Everything else — writing, moods, tasks, meditation, breathing, community, Umbrellas — keeps working.
  • Typed day-log entries are processed the same way, whether or not you use voice, so they can be sorted into tasks, moods and reminders. Sorting is not separately switchable from transcription today.
  • There is no way to use the day-log features while excluding this processing. If that matters to you, the reliable control is what you choose to put in.
  • Content processed this way is not end-to-end encrypted (section 9). Your Umbrella chats and DMs are, and are never sent for this processing.
  • Where the law needs your consent, we ask, and you can withdraw it (section 10).
  • None of this produces legal or similarly significant effects. We do not use it to decide eligibility for services, credit, employment or insurance.

4.5 Accuracy

Transcription, classification and assistant output is generated automatically and may be wrong, incomplete or unsuitable. It is not a clinical assessment. Do not treat it as a record of fact or as health advice.

5. Who receives your information

We do not sell personal data. The categories of recipient are below; the fuller version, including how providers may use your content, is at /legal/subprocessors.

CategoryWhat it receivesPurposeLocation
Database, file storage and authenticationAccount data, synced content, uploaded filesStoring and syncing your account and contentIndia
Website hostingWebsite requests, IP address, approximate countryServing the websiteUnited States and a global edge network
Sarvam and Groq — speech-to-text and language processingVoice recordings; transcripts; Assistant questions and limited relevant contextSarvam-first transcription, classification and Assistant replies; Groq transcription and Assistant fallbackUnited States and India
Sarvam — text-to-speechAssistant reply textProducing spoken assistant repliesIndia
PostHog EU Cloud — website analyticsPage views and feature events; internal account ID only after sign-inUnderstanding website usage and improving the productEuropean Union
Meta (Facebook) SDK — install measurementThat the app was opened and that an account was created; app and device model, OS version, app version; on iOS only Apple's privacy-preserving SKAdNetwork signal. No advertising identifier, and never any voice, transcript, mood, chat or contact contentMeasuring whether our ads on Instagram and Facebook led to installs, so we can spend less on ads that do not workUnited States
Push notifications and diagnosticsDevice and installation identifiers; crash data; notification tokensDiagnosing faults and delivering notificationsUnited States
Sign-in providersSign-in identifiersAuthentication, where you choose to sign in with a third-party accountUnited States
PaymentsTransaction and billing metadataProcessing voluntary gifts, if you choose to send oneIndia, United States and the European Union
EmailReported community content and report metadata; service email contentDelivering moderation alerts and service emailUnited States

Not every provider receives every request. For any category not named here, email hello@hushedechoes.com and we will identify the company used for your data.

Beyond those recipients, information may be shared:

  • With other users — whatever you choose to share, with the circle or community you share it into. Think before you post.
  • As aggregated or de-identified data that does not identify you, for any purpose.
  • For legal, safety and enforcement reasons — to comply with law or legal process, respond to a lawful request, enforce our Terms, prevent fraud or abuse, or protect people.
  • In a corporate transaction — a merger, acquisition, financing, reorganisation, insolvency or sale, subject to this policy or a successor.
  • When you tell us to.

6. Where your data lives, and crosses borders

Account data is stored in our primary database, hosted in India. Content sent to automated features is processed in the United States or India. Analytics, crash reporting, push, authentication, hosting, email and payment providers may process information in the United States, the EU and elsewhere.

If you are in the EEA or the UK, your personal data is processed outside the EEA and the UK — including its storage in India. Neither India nor the United States has a European Commission adequacy decision of general application, so these are restricted transfers requiring a safeguard under Chapter V of the GDPR. Our website analytics provider is EU-hosted and is not a restricted transfer.

For each recipient outside the EEA/UK we rely on an appropriate safeguard: the European Commission’s Standard Contractual Clauses, with the UK International Data Transfer Addendum where the transfer is from the UK; the EU–US Data Privacy Framework where the recipient is certified; or another Chapter V mechanism. We assess each transfer and apply supplementary measures where the assessment calls for them.

Ask which mechanism applies to a particular recipient at hello@hushedechoes.com.

7. Legal bases and grounds

EEA/UK (GDPR). We rely on:

  • Contract — to provide the Services you asked for.
  • Consent — for health-related and other special category data, for training our own models on your content, for non-essential cookies, for optional communications, and wherever else the law requires it. Withdraw any time. For special category data we rely on explicit consent under Article 9(2)(a).
  • Legitimate interests — security and abuse prevention, analytics and product improvement, internal research, business operations, and legal claims, where not overridden by your rights.
  • Legal obligation and, rarely, vital interests where life or safety is at risk.

India (DPDPA).

We process on the basis of your consent, given through the notice shown to you and this policy, and on the legitimate uses the DPDPA permits — including compliance with law and responding to a medical emergency or threat to life or safety.

8. How long we keep things

CategoryRetention
Data only on your deviceUntil you delete it or uninstall the app
Synced voice recordingsNormally removed around 14 days after capture; the transcript is the lasting record. Removal runs as a rolling sweep during ordinary use, so exact timing varies and we do not guarantee deletion on a fixed date.
Assistant audioDiscarded after transcription; a retry record may persist up to 24 hours
Assistant conversation contextCompact recent history and source references, up to 12 hours, so follow-up questions stay connected
Synced content (logs, transcripts, moods, tasks, messages)Until you delete it or delete your account, plus up to 30 days for backups to roll over
Account and billing recordsAs long as tax, accounting and legal obligations require
Content held by AI providersGroq customer content is configured for zero retention. Sarvam's standard content retention may be up to 30 days after last access, with usage logs up to one year, unless an agreement or deletion request shortens it
Aggregated and de-identified informationMay be kept indefinitely
Website product analyticsUnder our PostHog project retention settings while needed for product analytics; signed-out events have no HushedEchoes account ID and signed-in events may remain linked only to the internal account ID

Content already used to train a model cannot generally be withdrawn from it. Deleting your content stops future use; it does not reverse training already done.

9. Security, and the limits of encryption

We use measures appropriate to the risk: encryption in transit, encryption at rest, row-level access controls, and secure storage of credentials on your device.

Echoes are readable; chats are not.

Echoes: voice recordings and transcripts must be readable by our service so Sarvam can transcribe and classify them, with Groq used only as the speech-to-text fallback. Authorized HushedEchoes staff may access echo content only for the specific support, operations, security, abuse-investigation or legal need that requires it.

Chats and DMs: message content, including chat voice notes, is end-to-end encrypted using X25519 key exchange and XChaCha20-Poly1305 (via libsodium). Our service cannot read it even if we want to: the server stores and relays ciphertext, and the encryption keys never leave your device. Circle keys rotate when a member is removed.

The limits, stated plainly.

End-to-end encryption covers chats and DMs only. Voice day-logs, transcripts, moods, tasks and community posts are encrypted in transit and access-controlled, but are not end-to-end encrypted — the automated features in section 4 cannot operate on content we cannot read. Routing metadata (who talks to whom, and when) stays visible to us. A conversation only becomes encrypted once every participant is on a supporting app version. Because keys never leave your device, we cannot recover encrypted messages if you lose it or reinstall.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

10. Your rights and controls

  • Access — ask for a copy of what we hold about you.
  • Correct — fix inaccurate data, or edit it in the app.
  • Delete — individual logs, messages and tasks in the app, or your whole account from settings. Account deletion removes stored files as well as database rows. Deletion cannot reach content already sent to a third-party provider — we can stop sending, but we cannot retract what has been transmitted, and content already used to develop a model cannot be withdrawn from it. See sections 4.2 and 8.
  • Withdraw consent — including the model-training opt-in in section 4.3. It does not affect processing already carried out, and may make some features unavailable.
  • Object or restrict — where processing rests on legitimate interests, in the circumstances the law provides.
  • Portability — receive certain data in a structured, machine-readable format.
  • Nominate — nominate someone to exercise your rights on death or incapacity, as the DPDPA provides.
  • Complain — to the Data Protection Board of India, or your local supervisory authority in the EEA/UK.

Use the controls in the app or email hello@hushedechoes.com. We acknowledge within 48 hours and respond within 30 days, or sooner where the law requires. We may need to verify your identity first.

You can also turn notifications off, revoke microphone and calendar permissions, change the model-training opt-in at any time, and choose what you share. Public website pages can be read signed out; the mobile app requires a signed-in adult account.

11. Children

The Services are for adults 18 and over. The mobile app requires a signed-in account and a current adult-verification result before app data, storage, Realtime, AI or push services open. It asks Google Play or Apple for a privacy-preserving age range where available and otherwise performs a one-time birth-date threshold check without retaining the exact date in the app or mobile backend. An under-18 result blocks access. If you believe a minor is using the Services, tell us and we will delete the account and its data.

12. This is a wellness service, not a medical one

HushedEchoes is not a medical service, not a substitute for professional care, and not an emergency or crisis service. Anything in the app, including generated summaries and insights, is not a diagnosis or clinical advice. If you are in crisis or considering self-harm, contact a qualified professional or your local emergency services immediately. See our disclaimer and crisis resources.

13. Changes to this policy

We may update this policy. For material changes we will tell you in the app and, for signed-in users, by email, at least 14 days before the change takes effect. Where a change needs your consent, we will get it before applying the change to your data. The current version always lives at hushedechoes.com/privacy.

14. Contact, grievance officer and representatives

General and privacy enquiries: hello@hushedechoes.com

Grievance Officer (DPDPA and IT Rules)

Harshal Goyal

Email: hello@hushedechoes.com — subject line Grievance

We acknowledge grievances within 48 hours and resolve within 30 days. If you are unsatisfied, you may escalate to the Data Protection Board of India. The Grievance Officer is also the person who answers questions about our processing for the purposes of Rule 9 of the DPDP Rules, 2025.

Data Protection Officer

Jigar Vaishnav

Email: hello@hushedechoes.com — subject line Data Protection

EU and UK representatives (GDPR Article 27).

Because we are established outside the European Union and offer the Services to people in the EEA and the UK, we appoint representatives who may be contacted on all matters relating to our processing:

  • EU representative: Jigar Vaishnav.
  • UK representative: to be appointed before UK launch.

You may contact your local supervisory authority, or the Data Protection Board of India, at any time.