Privacy Policy
- We use your material and account data only to make, show and publish your posts.
- We never sell your data and never use your material to train AI models.
- The AI that reads your material runs on computers we control, not on outside AI services.
- We publish to YouTube only the videos you approve, and you can disconnect at any time.
- You can ask us to export or delete your data by writing to support@echoseed.app.
1. Who we are
Echoseed ("Echoseed", "we", "us") turns your books, sermons and teaching into social media posts that you review and approve. Echoseed is operated from the United Arab Emirates. This policy covers the website echoseed.app, the web app at me.echoseed.app, and the Echoseed Telegram bot (together, the "Service").
For the information you put into the Service, we act as the controller. When you upload material about other people, you are responsible for having the right to share it with us.
2. What we collect
| Information | Examples | Where it comes from |
|---|---|---|
| Account | Email address; your name and profile picture if you sign in with Google | You, or Google when you choose "Continue with Google" |
| Brand settings | Display name, handle, book title, author, writing rules, hashtags, colours, voice, posting times and time zone | You |
| Your material | Books, chapters, sermon notes and other files you upload | You |
| Content we make for you | Topics, post text, captions, images, slides, videos and your edits and approvals | The Service, from your material and settings |
| Telegram | The chat ID of the Telegram chat you link, and your Approve or Skip taps | Telegram, when you link the bot |
| YouTube | An access token for your channel; your channel ID, name and picture; the IDs and status of videos we upload for you | Google, when you connect YouTube (see section 4) |
| Billing | Your plan, billing period, subscription status and the Stripe customer ID. Card details go straight to Stripe; we never see or store them. | Stripe |
| Mailing list | Name, email, WhatsApp number, role, social account, language and what you teach, if you fill in the "Keep me posted" form | You |
| Support | Messages you send us | You |
| Technical | IP address, browser type and request logs kept by our hosting providers for security and reliability | Your device |
We do not use advertising trackers or sell any information.
3. How we use it
- To provide the Service: create your account, read your material, suggest topics, write and render posts, show them in the app, send them to your Telegram for approval, and publish the ones you approve. (Legal basis: performing our contract with you.)
- To bill you: manage your plan, trial and payments through Stripe. (Contract; legal obligations for tax and accounting records.)
- To keep the Service safe and working: prevent abuse, fix problems and enforce our Terms. (Our legitimate interests.)
- To talk to you: service messages about your account, and news and tips only if you opted in. You can unsubscribe at any time. (Contract; your consent for news.)
- To meet legal duties, such as answering lawful requests from authorities.
4. Google and YouTube data
If you choose Connect YouTube, you sign in with Google and allow Echoseed to use the YouTube API Services on your behalf. By connecting, you also agree to the YouTube Terms of Service, and Google's handling of your data is described in the Google Privacy Policy.
What we access and why
- Upload videos (
youtube.upload): to upload the videos you approve, with the title, description and publish time shown in the app. - View your YouTube account (
youtube.readonly): to read your channel's ID, name and picture so the app can show which channel is connected.
What we store
We store a refresh token for your channel, your channel ID, name and picture, and the ID, link and status of each video we upload for you. The token is kept in a part of our database that only our servers can read; the web app itself can never read it.
What we don't do
We do not share YouTube data with anyone, do not use it for advertising, do not sell it, and do not use it to train AI models. Echoseed's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Disconnecting
You can disconnect at any time in Echoseed under Settings → Publish to YouTube → Disconnect. This revokes our access at Google and deletes the stored token. You can also remove Echoseed's access from your Google account's security settings page. Videos already uploaded stay on your channel until you delete them in YouTube Studio. When access is revoked, we delete the stored token within 7 days at the latest, and other YouTube data within 30 days unless you ask us to keep your account.
5. AI and your material
Echoseed uses AI models to suggest topics, write post text and narration, make images and add subtitles. These models run on computers that we operate. Your material is not sent to outside AI services such as ChatGPT, and we never use your material or your posts to train or improve AI models. If we ever change this, for example to offer an optional cloud model, we will update this policy first and tell you in the app.
AI can make mistakes. That is why you review every post before it is published.
6. Who we share it with
We share information only with service providers that help us run the Service, under contracts that limit their use of it, and only as much as they need:
| Provider | What they do |
|---|---|
| Google Firebase (Google LLC) | Sign-in, database and file storage |
| Cloudflare, Inc. | Hosting of echoseed.app and me.echoseed.app, and the servers that handle Telegram, YouTube and payment connections |
| Stripe, Inc. and its affiliates | Payments, invoices and subscription management (Stripe Privacy Policy) |
| Telegram | Delivering posts to the chat you linked, if you use Telegram approval |
| Google / YouTube | Publishing the videos you approve, if you connect YouTube |
| Google Fonts | Serving the fonts on our pages (your browser requests them from Google) |
| Our own servers | A server we rent runs our automation (for example, forwarding "Keep me posted" sign-ups to our team) |
We may also disclose information if the law requires it, to protect people's safety or our rights, or to a buyer if Echoseed is sold or merged (the buyer must keep this policy's promises or tell you first).
7. Where it is stored
Our database is hosted in the European Union and uploaded files in the United States, by Google. Our providers may process data in other countries too. Where the law requires it, we rely on safeguards such as the providers' standard contractual clauses for these transfers. AI processing happens on our own computers.
8. How long we keep it
- Account, settings, material and posts: while your account is open. Files you delete in the app are removed from storage straight away.
- After you close your account: we delete your data within 30 days, apart from backups (which expire within 30 more days) and what we must keep.
- Billing records: as long as tax and accounting law requires (in the UAE this is generally five years).
- Mailing list: until you unsubscribe or ask us to delete it.
- YouTube tokens: until you disconnect, as described in section 4.
9. Your rights
Depending on where you live (for example under the UAE Personal Data Protection Law, the EU or UK GDPR, Nigeria's Data Protection Act, Kenya's Data Protection Act or South Africa's POPIA), you may have the right to:
- see the information we hold about you and get a copy of it;
- correct it if it is wrong;
- have it deleted;
- receive your material and posts in a portable format;
- object to or limit some uses, and withdraw consent you gave (such as for news emails);
- complain to your data protection authority.
Write to support@echoseed.app from the email on your account. We answer within 30 days. We may need to confirm it's really you before acting on a request.
10. Cookies and local storage
We do not use advertising or analytics cookies. The web app stores your sign-in session in your browser's local storage so that you stay signed in, and remembers small conveniences such as the email you used to request a sign-in link. Stripe's checkout and billing pages, which open on Stripe's own site, use cookies for fraud prevention as described in Stripe's policies.
11. Security
Data is encrypted in transit (HTTPS) and at rest by our hosting providers. Database access rules let each person see only their own workspace. Platform tokens are readable only by our servers. Secret keys are never put in the web app. No system is perfectly secure, so we will tell you without undue delay if a breach affects your data.
12. Children
The Service is for adults who run their own or their organisation's social accounts. It is not meant for anyone under 18, and we do not knowingly collect information from children. If you believe a child has given us information, contact us and we will delete it.
13. Changes
We will post any change to this policy on this page and update the date at the top. If a change is significant, we will also tell you by email or in the app before it takes effect.
14. Contact
Questions, requests or complaints: support@echoseed.app.