EchoPod · Privacy Policy
Last Updated: September 20, 2026

Privacy Policy

EchoPod (“we,” “our,” or “us”) respects your privacy. This Privacy Policy explains how we collect, use, and protect your information when you use our language learning app.

For a feature-by-feature description of transcription, translation, AI explanation, storage, and deletion, read How EchoPod processes audio and AI requests.

1. Information We Collect

Account Information

We collect your login credentials through the Supabase Flutter SDK to create and manage your account. This may include your email address or third-party login details (e.g., Google or Apple, if enabled).

Subscriptions and Purchase History

When you use subscription features, EchoPod sends your account identifier (a Supabase user ID), purchase and subscription records, and necessary app/device information to RevenueCat to validate purchases, restore access, and synchronize your membership. Apple or Google processes the payment; EchoPod does not receive your full payment-card number. We keep membership status and service usage counters on our Cloudflare backend to enforce your plan's limits and prevent duplicate grants.

We do not send your audio, transcript text, or chat prompts to RevenueCat. We do not use RevenueCat for advertising tracking. See RevenueCat's privacy policy.

App Usage Data

EchoPod stores account-linked usage counters and request identifiers for transcription, translation, and AI chat to enforce allowances, prevent duplicate charges, and recover interrupted requests. Your local library and playback progress also support the listening experience.

Podcast Search

Podcast search terms and language preferences are sent through our Cloudflare service to Podcast Index to return matching shows. Search requests do not include your EchoPod account ID. Our shared edge cache retains the query and matching results for up to 10 minutes to improve response times. Network and service logs may contain request metadata; this is not a promise that searches are anonymous. We do not use search terms for advertising tracking.

Crash & Performance Data

We rely on the Firebase Flutter SDK to collect anonymous crash logs and performance metrics. This helps us identify bugs and improve stability. The data does not identify you.

Device Information

We may gather technical metadata such as device type, OS version, and app build to ensure compatibility and troubleshoot issues quickly.

2. How We Use Your Information

  • Provide authentication and account services (via Supabase).
  • Validate, restore, and manage subscriptions (via RevenueCat and the store), and track service usage (Cloudflare).
  • Diagnose crashes and improve performance (via Firebase).
  • Deliver listening, echo training, and AI subtitle features.
  • Improve recommendations and track learning progress.
  • Communicate important updates or policy changes.

3. How We Share Your Information

We do not sell your personal data. We may share limited information only when necessary:

  • Service Providers
    • RevenueCat, Apple, and Google Play. Purchase validation, subscription management, and restoration.
    • Cloudflare and AI providers. Service usage, transcription, translation, and AI requests as described in our AI privacy notice.
    • Podcast Index and Cloudflare. Podcast searches and discovery, including shared search-result caching.
    • Supabase. Authentication and storage of account/progress data.
    • Firebase. Anonymous crash reporting and performance analytics.
  • Legal Requirements. When required to comply with applicable laws or legitimate requests.

4. Data Storage & Retention

  • Account and progress data are stored securely via Supabase.
  • Crash and diagnostics data are stored anonymously in Firebase.
  • Cloud transcription may temporarily copy audio to private Cloudflare storage. Processing copies are normally deleted when the request finishes; interrupted copies expire and are cleaned up automatically, with a one-day storage lifecycle as a backstop.
  • Transcription, translation, and non-streaming chat results may be cached privately for up to 24 hours for safe retries. Expired results are no longer served; background cleanup and a two-day storage lifecycle remove remaining objects.
  • You may request deletion of your account and related data at any time.

Subscription and usage records are retained while needed to provide your membership, handle refunds and support, prevent fraud, or meet applicable recordkeeping obligations. Deletion requests cover account-linked subscription data we control, subject to those obligations; store records are also governed by Apple's or Google's policies.

Account Deletion

The app shows the scheduled deletion date when you request account deletion. The current grace period is 28 days. Signing in and using an authenticated service during this period can cancel the request. After deletion, we remove account-linked service records and cached request results we control. A non-reversible hash of the account identifier may be retained to prevent delayed purchase notifications from recreating the deleted account. Store and RevenueCat purchase records may be retained for purchase support, fraud prevention, and legal recordkeeping; contact us for related deletion requests.

Step-by-step instructions, including how to request deletion without the app: How to delete your EchoPod account.

Deleting your EchoPod account does not cancel an App Store or Google Play subscription. Cancel through the original store before deleting your account if you want to stop renewal. An active subscription remains associated with its original EchoPod account; contact support before deletion if you need help accessing that account.

5. Your Rights

Depending on your region (e.g., GDPR, CCPA), you may have the right to access, correct, delete, or export your data, and to withdraw consent for certain processing. Contact us at echopod@clothpath.com to exercise your rights.

6. Security

We implement technical and organizational measures—alongside Supabase and Firebase security controls—to protect your data. However, no method of transmission or storage is completely secure.

7. Children’s Privacy

EchoPod is not intended for children under 13 years of age (or the minimum age in your country). We do not knowingly collect personal data from children.

8. Changes to This Policy

We may update this Privacy Policy from time to time. Updates will be posted in the app and/or on our website with a new “Last Updated” date.

9. Contact Us

If you have questions about this policy, contact us at echopod@clothpath.com.