EchoLogic provides a continuity layer for team decisions. When your organization uses EchoLogic, your organization is the controller of the content you put into it and we are a processor acting on its instructions.
An email address, the name you choose to show your team (optional), and the organization and department you belong to. We do not ask for a phone number or a job title.
Whiteboards, entries, canvases, notes, meeting transcripts you upload, and files you attach. This is the substance of the product: the record exists because you wrote it.
Your subscription status and how many seats your organization holds. Card details never reach our servers — checkout happens on Stripe and we store only the identifiers Stripe gives back.
Ordinary server logs, an audit trail of our own administrative actions, and your organization’s activity log, which its owners and admins can read and download.
Five sub-processors, and four of them handle the content you write:
| Processor | What it handles | Sees your content |
|---|---|---|
| Vercel | Hosting the app | Yes — requests pass through it |
| Supabase | Authentication, database, file storage | Yes — it stores it |
| Anthropic | Extracting decisions, risks and questions from what you write | Yes |
| OpenAI | Parts of the same extraction pipeline, and finding related items across boards | Yes |
| Stripe | Checkout, subscriptions, payment disputes | No |
Extraction is how the Continuity Index is built, so text you capture and transcripts you upload are sent to those model providers to be turned into structured events. They act as processors and do not train on it. If that is a problem for your organization, tell us before you start — it is not something we can switch off per-account today.
Content is scoped to your organization and, inside it, to departments. Nothing crosses that boundary unless someone in your organization explicitly shares it. An Executive role sees across departments; a member sees their own, plus whatever has been shared with them. A board turned into a public link is exactly that — public to anyone holding the link, until it is turned off. More on how this is enforced is on the security page.
Content lives as long as your organization does. When a board or a file is deleted it is removed from the live system; backups age out on their own schedule.
Everything else has a limit, and a daily job deletes what has passed it:
When an owner closes your organization’s account, everyone has 30 days to download their data, and an owner can change their mind during that time. After 30 days we permanently delete the organization, every board shared with it or filed in its departments, and the boards and accounts of members who belong to no other organization. We keep only what we must for tax and accounting, which Stripe holds.
You can also delete your own account from your Account page, on the same terms: 30 days to download your data and change your mind, then your account, every board you own and your sign-in are permanently deleted.
Depending on where you live you may have the right to access, correct, export or delete your personal data, and to object to some processing. You can download everything on your own boards from your Account page, and your organization’s owners and admins can download its data from the Company page. For anything else, ask your organization’s Executive first, since they control the workspace — or write to us and we will help. Requests reach us at privacy@echo-logic.ai.
If we change how any of this works we will update the date at the top, and material changes will reach account Executives by email rather than appearing quietly here.