The marketing site talks like Signal. The contract talks like a hosted forum. Both documents are public. Read the second one before you paste a community into chat-echo.com.
Privacy Policy, last updated 23 May 2026, live at app-echo.net/privacy:
Section 2.2: they prevent ban evasion with “IP/device-based restrictions and account linking.” Anonymous accounts still get that treatment. Terms section 10 repeats it.
Section 8 of the same policy, quoted because people skip it:
Encryption at rest for supported storage systems (disk / database volume encryption where configured by the operator). This is not end-to-end encryption of chat message contents; operators of a self-hosted instance and anyone with database access can read message bodies.
Voice and video calls may use separate client-side encryption where enabled. Text chat and group messages are not end-to-end encrypted in the current product.
The in-repo threat model, docs/security/e2ee-threat-model.md, agrees. Voice can use LiveKit client-side E2EE and MLS. The server still learns channel id, ordering, timing, sizes, author id, device identifiers, and who talks to whom. “Echo does not implement sealed-sender-style metadata minimization.” Identity is trust-on-first-use. XSS against the web origin can steal keys after decryption. Encrypted chat payloads from earlier builds “cannot be sent.”
If you wanted a private Discord, you wanted E2EE on the messages. Echo wrote that down, then kept the homepage word “privacy.”
Terms, 28 June 2026, section 4.2. By posting, you grant a worldwide, royalty-free, transferable, sublicensable license to use User Content to:
They say they do not sell personal data. They also say they may keep copies after you delete content, for backups, logs, security investigations, abuse prevention, and legal compliance. There is no default refund for paid features.
Homepage: “No ID verification, ever.” Terms section 2 and privacy section 10: they may require age or consent verification, including extra information from a parent or guardian, and they may lock the account until that happens. Children’s data is processed “only in line with applicable law.” The Service “is available to minors only where legally permitted.”
The contract has a switch. The homepage copy never mentions it.
Section 14 of the privacy policy is long because Google’s Limited Use rules are long. Echo stores Google sub, email, name, photo URL, OAuth access and refresh tokens, and YouTube channel identifiers. Live sessions can store broadcast ids, titles, privacy status, and watch URLs. An optional YouTube stream key is stored encrypted. Tokens are not supposed to hit the browser. Personnel “do not read Google user data except” for support you agree to, security, law, or aggregated internal operations.
A privacy-first chat app that also wants to be your YouTube encoder is a different product than the homepage card.
They use automated systems to classify content, detect abuse, rank or limit visibility, and trigger enforcement: remove content, warn, limit access, suspend, terminate. Human review exists “where required by law.” Community guidelines restrict NSFW to 18+ servers and 18+ private chats. Graphic real-world violence is banned. Self-promotion is banned. Alt accounts are banned. Bots that simulate users are banned unless the platform authorizes them.
The 1.0.0 notes include a “CSAM scan service integration hook.” Echo’s own legalPrerequisites.ts enumerates operator obligations (PhotoDNA, NCMEC, retention) as documentation a self-hoster or the eventual operator still has to wire up. chat-echo.com is already a public instance.
“We operate as a registered business in Germany (Kleingewerbe).” Support email: [email protected]. Governing law: Germany. No arbitration. They do not guarantee uptime, security, or that the service is error-free. You use it at your own risk. They are not liable for loss of data “to the maximum extent permitted by law.”
Kleingewerbe is a small-business registration for a sole trader. The policy still says “the team.”