Privacy Policy
Last updated: March 2026
EchoRecorder ("we", "us", "our") is a screen recording platform for teams. This policy explains what data we collect, how we use it, and your rights.
1. Data We Collect
Account Information
When you sign up, we collect your email address and name. If you use Google Sign-In, we receive your name, email, and profile photo from Google.
Recordings
When you record, the following data may be captured depending on your settings: screen video, microphone audio, tab/system audio, webcam video, and click events (mouse positions and timestamps used for click tracking overlays).
View Analytics
When someone watches a shared recording, we collect anonymized analytics: view count, watch duration, approximate location (country/region from IP), and playback engagement data. We do not track individual viewers across recordings unless they are logged in.
2. How We Use Your Data
We use your data to: store and deliver recordings securely via our CDN; generate transcriptions using OpenAI Whisper (speech-to-text); generate AI documentation via OpenAI GPT-4o Vision when you explicitly trigger it; power your analytics dashboard with anonymized viewing data; and authenticate your account and team membership.
3. Data Storage & Security
Recordings and files are stored in Amazon Web Services (AWS) S3, delivered via AWS CloudFront CDN. All transfers use HTTPS/TLS encryption. Files at rest use S3 server-side encryption. Account and metadata are stored in PostgreSQL hosted on Railway over encrypted connections. Authentication uses JWT tokens in HttpOnly, Secure, SameSite cookies.
4. Data Sharing
We do not sell your data. We do not share your recordings or personal information with advertisers or data brokers. We use the following third-party processors:
Amazon Web Services (AWS) — file storage (S3), content delivery (CloudFront), email delivery (SES).
OpenAI — transcription (Whisper) and AI document generation (GPT-4o Vision), only when you use these features.
Railway — application and database hosting.
5. Data Retention & Deletion
Deleting a recording permanently removes the video file from S3, all associated data (transcript, thumbnails, analytics, comments, AI documents), and the database record. Free plan recordings are subject to a 30-day retention policy. Deleting your account removes your profile, all your recordings, and disassociates you from any teams — use the account deletion option in your profile settings.
6. Your Rights
You have the right to: delete any recording you own at any time; control visibility (public, private, password-protected, team-only); delete your account and all associated data; and download your original recording files. To request access to or deletion of your data, contact us at the address below.
7. Chrome Extension Permissions
The EchoRecorder Chrome Extension requests these permissions: activeTab (access current tab only when you click to record), storage (save preferences locally), offscreen (hidden page for MediaRecorder), scripting (inject click-tracking during recording), tabs (read tab URL/title for auto-naming), identity (Google Sign-In), and host permissions (all URLs) (record any tab and inject click overlay — only during active recording you initiate).
8. Social Platform Integration
On supported platforms (LinkedIn, X, Facebook), the extension adds an "Attach Recording" button to the message compose area. This does not read or access your message content, contacts, or any platform data — it only inserts a share link to your selected recording.
9. Cookies
We use essential cookies for authentication (JWT tokens in HttpOnly, Secure, SameSite cookies). We do not use third-party advertising cookies. Analytics are handled through our own view-tracking system, not third-party trackers.
10. Contact
For privacy questions or data requests, contact us at [email protected].