Legal

Privacy Policy

Last updated: 15 June 2026

This Policy explains, in plain terms, what Echobit collects, how we use it, and the choices you have. Echobit is operated by Devmorphix.

1. Who We Are & Scope

Echobit (the "Service") is an AI meeting recorder, transcriber, and summariser operated by Devmorphix ("we", "us", "our"). You can learn more about us at devmorphix.com.

This Privacy Policy explains what personal data we collect, how and why we use it, who we share it with, and the choices and rights you have. It applies to the Echobit Android app and our website and web app (together, the "Service"). By creating an account or using the Service, you agree to this Policy and, where required by law, provide your consent to the processing described here.

For the EU/UK GDPR, Devmorphix is the "data controller". For India's Digital Personal Data Protection Act, 2023 ("DPDP Act"), we are the "Data Fiduciary". The providers listed in Section 5 act as our processors.

2. Information We Collect

  • Account information — your name, email address, and password (stored only as a salted hash). If you sign in with Google, we receive your name, email, Google account identifier, and profile picture.
  • Profile details — optional information you provide, such as your country, profession, and preferred recording and summary languages, used to tailor the Service to you.
  • Audio recordings — the audio you record in the Service. With Cloud Sync on, recordings are uploaded and stored securely in the cloud. With Cloud Sync off, audio stays in the app's private storage on your device; it is sent to our processors only transiently for AI processing and is not retained on our servers afterward.
  • Transcriptions, summaries & notes — text we generate from your recordings — transcripts, AI summaries, meeting minutes, and action items — along with the titles, tags, and any notes you add.
  • Payment information — when you subscribe to a paid plan, payments are processed by Razorpay. We receive your subscription and plan status, but we never see or store your full card or banking details.
  • Usage & log data — limited records needed to run and secure the Service: sign-in timestamps and login counts, your plan and subscription status, app/device and operating-system information for compatibility and debugging, and your IP address (processed transiently for security, abuse-prevention, and rate-limiting — see Section 5).
  • Support communications — if you contact us via our contact form or by email, we receive your name, email, and the contents of your message.

3. Recordings & Sensitive Information

Recordings and the transcripts derived from them may contain sensitive personal information — for example, health details dictated in a consultation, or financial, religious, or political matters discussed in a meeting. Where this is "special category" data under the GDPR or "sensitive" data under applicable law, we process it only on the basis of your explicit consent, which you give by choosing to record and process that content. You can withdraw this consent at any time by deleting the relevant recordings or your account.

Recording other people. When you record a meeting or conversation, you may capture the voice and personal information of other participants. You are responsible for obtaining any consent or legal right required to record and process other people's data in your jurisdiction (some regions require the consent of all parties). You agree to use Echobit lawfully and to honour requests from participants regarding their data.

We do not use your recordings, transcripts, or notes to build advertising profiles, and we do not use them to train our own AI models.

4. How We Use Your Information & Legal Bases

We use your information to:

  • Provide the Service — record, transcribe, summarise, and store your meetings, and manage your account and subscription. (Legal basis: performance of our contract with you.)
  • Process sensitive content in recordings — as described in Section 3. (Legal basis: your explicit consent.)
  • Secure the Service — authenticate you, verify your email, reset passwords, and prevent fraud and abuse (including rate-limiting and bot protection). (Legal basis: legitimate interests; transactional email is part of providing the Service.)
  • Maintain and improve the Service — debugging, reliability, and aggregate, non-identifying analysis of feature performance. (Legal basis: legitimate interests.)
  • Comply with the law — meet legal, tax, and regulatory obligations and respond to lawful requests. (Legal basis: legal obligation.)

We send transactional messages such as verification and password-reset codes. We do not send marketing emails without your consent, we do not sell your personal data, and we do not use it for third-party advertising.

5. AI Processing & Service Providers

We share data with a limited set of trusted providers ("processors") strictly to operate the Service. Each processes your data only on our instructions and under data-protection terms:

  • Cloudflare — hosting and content delivery, secure audio storage (R2), database (D1), serverless compute (Workers), transactional email delivery, and bot/abuse protection (Turnstile). As our infrastructure provider it inherently processes IP and request data. Our forms use Turnstile in invisible mode to silently block automated abuse; this processing is governed by the Cloudflare Turnstile Privacy Addendum. (USA / global.)
  • Cloudflare Workers AI — Whisper — speech-to-text transcription of your recordings, processed on Cloudflare's network.
  • Sarvam AI — speech-to-text and translation for Indian languages; the relevant audio and text are sent for processing. (India.)
  • Google Gemini — generates summaries, meeting minutes, and action items from your transcripts; the relevant text is sent for processing. (Google LLC, USA / global.)
  • Google Sign-In — optional OAuth login; if used, it is governed by Google's Privacy Policy. (Google LLC, USA / global.)
  • Razorpay — payment processing for paid plans; Razorpay handles your card/banking data as a controller under its own privacy policy. (India.)

These providers are contractually limited to processing your data only to provide their services to us. We do not use your content to train AI models.

6. International Data Transfers

Echobit is operated from India, and our providers operate in India, the United States, and other countries. As a result, your personal data may be transferred to and processed outside your country of residence, including outside the EEA and the UK.

Where we transfer personal data internationally, we rely on appropriate safeguards — such as the European Commission's Standard Contractual Clauses (with the UK Addendum) and our providers' data-processing agreements — so that your data stays protected. Under the DPDP Act, we may transfer data outside India except to any country restricted by the Government of India.

7. Sharing & Disclosure

We do not sell or rent your personal data, and we do not share it for cross-context behavioural advertising. We disclose personal data only:

  • to the processors listed in Section 5, to run the Service;
  • to comply with the law, enforce our Terms, or respond to valid legal requests;
  • to protect the rights, safety, and security of our users, the public, or Echobit; and
  • in connection with a merger, acquisition, or sale of assets — in which case we will notify you, and this Policy will continue to protect your data.

8. Data Retention

  • Account & content — kept while your account is active. When you delete your account, your recordings, transcripts, summaries, notes, and profile are permanently deleted from our live systems and purged from encrypted backups within 30 days.
  • Deletion requests — processed within 7 business days of a verified request.
  • Verification & reset codes (OTPs) — short-lived and expire within minutes.
  • Security & error logs — kept only for a limited period for debugging and abuse-prevention, then deleted or de-identified.
  • Local-only recordings — audio saved with Cloud Sync off lives only in the app's private storage on your device and is removed when you delete it or uninstall the app. Export or enable Cloud Sync to keep important recordings.
  • Legal records — we may retain limited records (such as transaction or tax records) for as long as the law requires.

9. Data Security & Breach Notification

We use industry-standard safeguards including HTTPS/TLS encryption in transit, salted password hashing (bcrypt / PBKDF2), token-based (JWT) authentication, access controls on stored audio, and reputable infrastructure providers. No method of transmission or storage is completely secure, but we work to protect your data and to limit who can access it.

If a personal-data breach occurs that is likely to affect your rights, we will notify the relevant supervisory authority and affected users without undue delay, as required by the GDPR, the DPDP Act, and other applicable laws.

10. Your Privacy Rights

Subject to your local law, you have rights over your personal data, including to:

  • Access the data we hold about you and request a copy;
  • Correct inaccurate or incomplete data;
  • Delete your account and data (see Section 12 or our account deletion page);
  • Port your data to another service in a structured, machine-readable format;
  • Restrict or object to certain processing; and
  • Withdraw consent at any time, without affecting processing already carried out.

To exercise any of these rights, use the in-app controls or email us at support@echobits.xyz. We will respond within the timeframes required by law and will not discriminate against you for exercising your rights.

EEA & UK (GDPR): you may lodge a complaint with your local data-protection authority (for example, the UK ICO or your EU supervisory authority).

California (CCPA/CPRA): you have the right to know, delete, and correct your personal information and to opt out of its "sale" or "sharing". We do not sell or share your personal information, and we do not discriminate against you for exercising your rights.

India (DPDP Act, 2023): you may access, correct, update, and erase your data, nominate someone to exercise your rights in the event of death or incapacity, and raise grievances with our Grievance Officer (Section 14). If unresolved, you may complain to the Data Protection Board of India.

11. Children's Privacy

Echobit is not intended for children. We do not knowingly collect personal data from anyone below the age of digital consent in their jurisdiction — 18 in India (where processing a child's data requires verifiable parental or guardian consent), 16 in much of the EEA (subject to member-state law, with a minimum of 13), and 13 in the United States and several other countries.

We do not knowingly profile children or serve them targeted advertising. If you believe a child has provided us personal data without appropriate consent, contact us and we will delete it promptly.

12. Cookies & Local Storage

We use only strictly necessary storage. Our web app stores a sign-in token in your browser's local storage to keep you logged in, and the mobile app stores equivalent data on your device. We do not use advertising or cross-site tracking cookies, and we do not run third-party ad networks.

13. Changes to This Policy

We may update this Policy from time to time. When we make material changes, we will update the "Last updated" date above and, where appropriate, notify you in the app or by email. Your continued use of the Service after an update means you accept the revised Policy.

14. Contact Us & Grievance Redressal

If you have questions, requests, or complaints about this Policy or your data, contact us:

We aim to acknowledge grievances promptly and resolve them within the timeframes required by applicable law.