Privacy Policy
Last updated: 2026-08-08
This document explains what Echoh collects, why, how we use it, and how to delete it. If anything here is unclear, please get in touch.
What we collect
- Slack workspace metadata when you install Echoh: team ID, team name, the bot token issued to us, and the Slack user ID of the admin who ran the install.
- Slack user identifiers for every teammate who links their account: Slack user ID and display name.
- LinkedIn identifiers when a user connects their LinkedIn: profile ID, name, profile picture URL. We do not store LinkedIn access tokens directly — those live in Nango, our OAuth provider (see "Third parties" below).
- Google identifiers if you sign in to the app dashboard: email, name, profile picture from Google OIDC.
- Post content you compose and publish through Echoh, plus the resulting LinkedIn post URN and URL.
- Engagement records for every amplify DM: which teammate received it, whether they reacted (and with which reaction), commented, reposted, opened, or skipped.
- Comment text that teammates post to LinkedIn through Echoh (so we can display it in the author's notification and the dashboard).
- Operational logs: server logs of API calls we make on your behalf, error traces, and timing metrics.
What we don't collect
- Your LinkedIn or Google passwords.
- Your Slack messages outside of DMs to the Echoh bot itself.
- Your LinkedIn feed, connections, or private data beyond what you explicitly publish through Echoh.
- Payment information (we're free during beta).
How we use it
Data is used solely to deliver Echoh's core product: publishing posts you compose, delivering Slack notifications to teammates, executing the LinkedIn actions they take, and showing you engagement analytics. We do not sell, rent, or share your data with advertisers.
Third parties we pass data through
- Slack — for the workspace, bot user, and DMs.
- LinkedIn — for publishing posts and executing reactions/comments/reshares.
- Nango — an OAuth provider that stores our LinkedIn refresh tokens on our behalf so we don't hold them ourselves.
- Google — for OIDC sign-in on the app dashboard.
- Neon (Postgres) — our primary database.
- Google Cloud (Cloud Run + Secret Manager) — application hosting and secret storage.
- DeepSeek, OpenAI, and Google Gemini — for AI drafting features (used only when you explicitly request an AI-generated draft).
Data retention + deletion
When you disconnect your LinkedIn account from the dashboard, we delete the associated LinkedIn identifiers and revoke the OAuth connection at Nango. When you uninstall Echoh from Slack, we soft-delete the workspace record with a 30-day grace period, then permanently delete it and all associated posts, amplifications, and comment records. You can request faster deletion by contacting us.
Rights (GDPR, CCPA)
If you are in the EU/EEA or California, you have the right to access, correct, port, or delete personal data we hold about you. To exercise these rights, contact us through our contact page.
Contact
Questions or requests about privacy? See our contact page.