Privacy Policy
Effective September 20, 2026
Scope
EchoReply is operated by Chase Baker, doing business as EchoReply (“EchoReply,” “we,” “us,” or “our”).
This policy explains how EchoReply accesses, uses, stores, shares, and deletes information when an authorized business owner uses echoreply.app. EchoReply helps owners review and post replies to new Google Business Profile reviews. It is not a patient-record system and should not be used to submit protected health information.
Information we receive
- Identity and account data: your Google-authenticated email address, Supabase identity identifier, acceptance/consent records, and first-touch campaign parameters such as UTM values or a GCLID when present.
- Google Business Profile authorization: encrypted OAuth access and refresh grants, token expiry, the account/location resource identifiers needed to operate locations you select, and a one-way pseudonym derived from Google's stable account subject and our Cloud project. That pseudonym is stored while a live connection or related revocation safeguard needs it, solely to prevent grant-wide revocation from disrupting another live connection. Completed revocation and cancellation records are unlinked after the OAuth race-protection window. Location names and addresses are used transiently during selection; the saved location label is supplied by you.
- Google review content: for eligible new reviews, reviewer display name, star rating, comment, timestamps, current owner-reply state, your draft, and publication state.
- Billing and service state: Stripe customer, subscription, Checkout, invoice-related status, quantity, renewal/cancellation state, and operational reconciliation identifiers. EchoReply does not receive your full card number.
- Support correspondence: your email address, the messages and attachments you choose to send, and our replies. Please do not send patient information, review text, passwords, or payment-card details.
- Operational and recovery data: minimal event names, timestamps, job health, retry counters, security/rate-limit state, generic error classes, and a randomly generated restore guard for each account. A keyed digest of that guard—not an email address, provider identifier, or local account number—is used to keep an independently stored account-deletion tombstone. Operational alerts are designed not to contain Google review content.
How information is used
- • Authenticate you and preserve your explicit consent choices.
- • List eligible locations that your Google account manages.
- • Read new reviews, create the draft you see, notify you, and post only an approved or specifically authorized reply.
- • Prevent duplicate ingestion or posting and reconcile uncertain provider results.
- • Process subscriptions, location quantity changes, cancellation, support, security, deletion, and service health.
- • Measure a limited account funnel and, only when configured, a verified purchase conversion without Google-derived review, reviewer, location, rating, or health data.
We do not sell Google user data or use Google review content for advertising, credit, insurance, surveillance, model training, or unrelated product purposes.
AI processing and automatic actions
After your specific consent, the new review's rating and text are sent to OpenAI solely to generate the visible reply draft. EchoReply deliberately omits the reviewer display name and your business/location label from the model request. Generated text must pass automated rules before it may enter the approval workflow, but those rules cannot identify every private, clinical, identifying, inaccurate, or otherwise unsuitable statement. You remain responsible for reviewing editable reply text before approval.
Omitting those separate name fields does not remove names or other personal information that a reviewer includes in the review text itself. That text may be included in the AI request.
Manual approval is the default. If you separately enable automatic replies for a location, EchoReply may post only its disclosed generic, content-free response for new four- or five-star reviews. You can disable this authorization at any time; already posted Google replies are not automatically removed.
Service providers and disclosures
- Google: identity sign-in and Business Profile location, review, and reply operations.
- Supabase: authentication and Google identity session exchange.
- OpenAI: AI draft generation after consent.
- Stripe: Checkout, subscription billing, refunds where applicable, and the customer billing portal.
- Twilio, if you opt in to SMS: your mobile number, verification and opt-out messages, generic draft-ready alerts, and delivery metadata. Generic alerts contain no review content. If you separately enable text-only review handling, Twilio and your carrier also process the location label, rating, full review text, draft replies, and replacement replies you text. We omit the separate reviewer display-name field, but review text itself may include personal information. Mobile information and SMS consent are not shared with third parties for their marketing or promotional purposes.
- Resend: transactional review and operational email delivery.
- Support email providers, including Google Gmail: receiving, forwarding, storing, and responding to messages sent to our support address.
- Hosting and backup providers, including Amazon Web Services S3/KMS: encrypted transport, application operation, database storage, immutable recovery archives, and deletion tombstones.
- Google Ads, only if enabled: the purchase amount, currency, and Stripe transaction identifier. Google's browser tag may associate the conversion with Google Ads identifiers under Google's controls. EchoReply does not insert its stored UTM/GCLID fields or any Google Business Profile content into that conversion event.
We may also disclose information when legally required, to protect the service and users, or as part of a business transaction subject to appropriate notice and safeguards.
Optional SMS alerts
SMS is optional. We store your mobile number, consent time, and verification time to deliver alerts. Verification codes expire after 15 minutes and are stored only as keyed hashes. Reply STOP or disable SMS in Settings to stop alerts; disabling in Settings removes the stored number and SMS alert/text-review consent and verification fields. Replying STOP clears consent and verification while retaining the number until you remove it or delete your account. Recovery snapshots omit phone numbers, SMS consent, and verification fields. We retain keyed, non-content receipts to prevent repeated webhook processing; completed receipts contain no phone number or account identifier. Until redaction succeeds, a cleanup record also retains the provider message identifier. For text-review messages, we request removal of the provider message body after processing or delivery and retry failed cleanup. This does not erase carrier/device copies, provider request logs, or records the provider separately retains for compliance. Twilio and mobile carriers may retain their own messaging records under their policies.
Google API data commitments
EchoReply's use and transfer of information received from Google APIs will comply with the Google API Services User Data Policy, including its Limited Use requirements, and the Business Profile API policies. We request business.manage because reading reviews and posting authorized replies require it, and openid only to identify the granting Google principal for safe, project-wide token revocation. This connection does not request Google email or profile scopes.
Retention and security
Account identity, consent history, your location labels, campaign attribution, and billing/service records are retained while your account exists, including when a subscription is canceled or inactive. Canceling a subscription does not delete your account. When account deletion completes, we remove connected locations and their retained review content, delete the linked Supabase identity, and clear the account's email, phone, consent, and campaign fields. Limited billing and operational records, including Stripe customer and subscription identifiers and deletion status, remain for billing reconciliation, dispute handling, security, and recovery safeguards; they are not subject to an automatic expiration period in the current service. These identifiers may still be linkable to your Stripe records.
Support emails are stored separately from your EchoReply account and are not automatically removed by deleting the account. Retention depends on the support issue, unresolved billing or legal matters, and mailbox retention settings; we do not currently apply a fixed automatic deletion period to support correspondence. Contact us to request review or deletion of these records, subject to applicable retention obligations.
Google-derived review content is stored only for the active product workflow and is automatically deleted before it is 30 calendar days old. A keyed, non-content receipt may remain so a deleted review is not re-imported; it does not contain the Google review ID, reviewer, rating, text, or reply. Pending OAuth location-selection information expires after approximately 30 minutes.
Sanitized recovery snapshots exclude Google review content and are encrypted with a dedicated provider-managed key. Each snapshot is locked against modification for 30 days and then scheduled for permanent lifecycle deletion; the storage provider processes eligible deletions asynchronously, so physical removal may occur after the scheduled expiration time. To prevent an older snapshot from restoring a deleted account, an opaque account restore guard remains with the limited operational records described above. Its independently stored keyed deletion tombstone is locked for 10 years and then scheduled for lifecycle deletion, which the storage provider processes asynchronously. The guard and tombstone are used solely for deletion replay. The tombstone contains no email address, business or reviewer data, Google or Stripe identifier, or local account number.
OAuth grants are encrypted at rest. Connections, billing work, provider revocation, and account deletion use durable retry state. Transport security, access controls, CSRF protection, scoped database access, minimal logging, and backups reduce risk, but no system can guarantee absolute security.
Account deletion does not immediately erase an existing immutable recovery snapshot. A snapshot may retain account and billing records and encrypted authorization-cleanup records until its archive retention expires; deletion safeguards prevent a restored snapshot from reactivating a deleted account. Service providers may separately retain records under their policies and applicable legal requirements. In particular, subscription cancellation does not erase Stripe's payment records, and deleting EchoReply data does not remove reviews or replies already published on Google. Our 30-day review-content limit describes EchoReply's own retained workflow content, not a promise that every provider deletes all of its records within that period.
Your choices and deletion
You can change the alert address, rename a location, disable automatic replies, withdraw AI-processing consent, reconnect Google, remove a location at renewal, disconnect a location immediately, or open Stripe's billing portal from Settings.
Immediate disconnect deletes locally retained review content for that location and queues revocation of a Google grant once it is no longer shared by another location. An account-deletion submission disables access and processing immediately. EchoReply confirms acceptance only after its independent, non-identifying recovery tombstone is verified, then proceeds to subscription cancellation, Google-content erasure and grant revocation, identity deletion, and account anonymization. If that independent safeguard is temporarily unavailable, the service stays inaccessible, reports that confirmation is pending, alerts operations through health monitoring, and retries automatically. Provider outages may delay later steps, but access is not restored while deletion is pending.
Children, changes, and contact
EchoReply is a business service and is not directed to children. We may update this policy when data practices change; where required, we will present the new version and request renewed consent before using Google data in a new way.
For privacy, access, or deletion questions, email hi@echoreply.app. Do not include review text, patient information, or credentials in email.