Privacy Policy

Last updated: April 16, 2026

Who we are

EchoReply ("we", "us", "our") is a review management service that helps local business owners monitor and respond to their Google reviews. Our service is available at echoreply.app.

What we collect

  • Account information — When you sign up, we collect your email address and a hashed (never plain-text) password.
  • Business information — Business name, address, and the Google Place ID or Google Business Profile location you connect.
  • Google OAuth tokens — If you connect your Google Business Profile, we store an access token and refresh token to fetch your reviews and post replies on your behalf. These are stored securely and used only for your account.
  • Review data — We fetch and store your Google reviews (reviewer name, rating, text, date) to generate AI response drafts. This data comes from Google's public APIs.
  • Phone number (optional) — If you enable SMS alerts, we store your US phone number to send review notifications via Twilio.
  • Payment information — Subscription payments are processed by Stripe. We never see or store your credit card number — only a Stripe customer ID and subscription status.

How we use your data

  • • To monitor your Google reviews and generate AI-drafted responses
  • • To send you email and SMS alerts when new reviews arrive
  • • To post approved responses to Google on your behalf (if auto-reply is enabled)
  • • To send weekly summary reports to your alert email
  • • To manage your subscription through Stripe

We do not sell your data. We do not use your review data for any purpose beyond operating EchoReply for your account.

Third-party services

  • Google — We use Google's Business Profile API to read reviews and post replies. Your use of Google's services is also governed by Google's Privacy Policy.
  • Anthropic (Claude AI) — Review text is sent to Anthropic's API to generate response drafts. Anthropic's data usage policies apply.
  • Resend — We use Resend to send transactional emails (review alerts, weekly reports). Your email address is shared with Resend for delivery.
  • Twilio — If you opt in to SMS alerts, your phone number is shared with Twilio to deliver text messages.
  • Stripe — All payment processing is handled by Stripe. We share only the information Stripe requires to process your subscription.

Data storage and security

Your data is stored in a secure database on our hosting provider. Passwords are hashed with bcrypt and never stored in plain text. OAuth tokens are stored encrypted at rest. We retain your data for as long as your account is active. When you cancel your subscription, your data is retained for 30 days before deletion.

SMS messaging

If you opt in to SMS review alerts, message frequency varies based on your review volume. Reply STOP at any time to opt out. Message and data rates may apply. For help, reply HELP or contact us at the email below.

Your rights

You can update or delete your account information by contacting us. You can disconnect your Google account at any time from your Settings page. You can opt out of SMS messages by replying STOP or by clearing your phone number in Settings.

Contact

Questions about this policy? Email us at hi@echoreply.app.