1. Scope
LazyingArt LLC operates EchoMind ("EchoMind," "we," "us," or "our"). This Policy applies to personal data handled through the EchoMind mobile applications, website, AI and language tools, social features, games, notifications, and OnlyIdeas paper workspace (together, the "Service").
The first native release is free. Native Release builds do not offer purchases, paid subscriptions, donation checkout, or external-payment promotion.
2. Information we collect
Account information
We collect a username, email address, password credential, invitation information, account status, and authentication records. Passwords used for password registration are stored as hashes rather than readable text. If Google or Apple sign-in is offered and you choose it, we receive a provider-specific account identifier, verified email, optional profile name, and authentication metadata. For Apple accounts, EchoMind can retain an encrypted revocation credential so account deletion can revoke the provider authorization. You may also provide a first name, last name, avatar, language preferences, voice preferences, and other settings.
Language-assistant conversations and AI content
We process prompts, messages, AI responses, conversation metadata, optional memory items, selected language enhancements, voice-model choices, generated audio, and processing status for the language-oriented AI chat. AI output and language enhancements may be inaccurate.
Standalone AI Agent conversations and tasks
The separate AI Agent workspace stores its own conversation titles, messages, selected mode and naming preference, task requests and results, status and error records, model routing, usage or quota records, provider attempts, sources, and timestamps. These records support requested chat or research work, recovery, cancellation, and synchronization; they are not the language-assistant conversation history.
Standalone AI Agent attachments
When you select an image, PDF, audio file, or supported text document for an Agent turn, we process its filename, type, size, hash, private storage reference, bounded extracted or normalized content, thread, task, and message relationships, processing leases, lifecycle state, and cleanup timestamps. Raw attachment payloads are kept outside the public upload tree. Unattached or unfinished payloads become eligible for cleanup after 24 hours, and raw payloads attached to a task are scheduled for file-first cleanup when that task reaches a terminal result. Bounded lifecycle records and task content can remain with an archived Agent thread until account deletion. Archiving a conversation is not the same as deleting it. Backup and downstream-provider copies can follow different expiry schedules.
Voice and media
If you choose voice, attachment, avatar, camera, QR, or paper features, we process the audio, transcript, image, file, or PDF you select, together with file metadata and generated or converted content.
Social and communications data
We store posts, comments, visibility, reactions, follows, friendships, direct messages, group membership and messages, images, voice messages, edits, read state, invitations, blocks, and moderation reports needed to provide those features. Other users can receive or view content based on the audience you select and the relevant group or conversation membership.
Research workspace data
OnlyIdeas can process uploaded papers, filenames, file hashes, selected page ranges, structured transcriptions, scholarly search queries and results, search history, paper briefs, and paper-grounded discussion. When standalone Agent public-web research is enabled and requested, its research query, returned sources, and generated result are also processed as Agent and search activity. Do not upload material you lack permission to process or disclose.
Device, notification, and usage data
We process device and app identifiers, platform and app version, push tokens and endpoints, notification and sync state, feature usage counts, game activity and results, timestamps, user agent, and diagnostic or security records. Network, hosting, proxy, CDN, and configured provider operators can receive an IP address and ordinary request headers. EchoMind records request or task identifiers, errors, timing, and security events. The first native release contains no dedicated advertising or general-purpose analytics SDK.
Transaction data
The first native release does not include donations, subscriptions, purchases, or external checkout. If commerce is introduced later, this Policy and applicable store declarations will be updated before release.
3. How we use information
We use the information described above to:
- Create, authenticate, secure, and support accounts.
- Provide AI chat, optional language enhancements, voice features, social communication, games, notifications, synchronization, and OnlyIdeas.
- Preserve drafts, deliver queued content, and recover from interrupted connections.
- Personalize language, voice, display, and optional memory behavior.
- Enforce usage limits, prevent abuse, investigate reports, and protect users.
- Send confirmation, password-reset, service, and security communications when email delivery is configured.
- Operate, diagnose, and improve reliability.
- Meet legal obligations and enforce our terms.
Where a jurisdiction requires a legal basis, EchoMind relies on performance of the user agreement to create an account and provide requested features; the user's affirmative feature choice or device permission for optional media, voice, notification, AI, and public-sharing actions; LazyingArt LLC's legitimate interests in securing, operating, debugging, moderating, and preventing abuse of the Service where those interests are not overridden by the user's rights; and compliance with legal obligations or valid legal process. Where consent is required, it can be withdrawn for future processing through the relevant setting or by contacting EchoMind. A feature will not be offered in a territory where its required basis or notice has not been established.
4. AI and automated processing
EchoMind sends the content and context needed for a requested AI feature to the configured model provider. Supported integrations can include OpenAI and DeepSeek, and the deployed Service can select or fall back between approved providers. The standalone AI Agent and OnlyIdeas research routes use an internal sandboxed worker path for bounded chat, task, attachment, paper-search, and explicit public-research requests. Internal sandboxes and loopback relays are execution boundaries, not additional third-party providers; the external model or speech operator reached through them receives the selected data.
Voice data can be sent through an internal relay to the configured speech-to-text operator, and text can be sent to the configured text-to-speech operator. OnlyIdeas can query Crossref when you request scholarly metadata. Paper-conversion and transactional-email features are available only when their providers are configured and approved for the deployed Service.
Configured provider categories can include AI model services, speech operators, Google services for Android identity, push, and paired Wear transport, Apple services for iOS identity and push, Crossref, and hosting, database, storage, and content-delivery operators. We do not promise that a provider has zero retention, is training-opted-out, or processes in a particular region unless its approved terms and deployed configuration establish that fact. You can avoid a provider-dependent optional feature by not using that feature.
Do not rely on AI output as professional medical, legal, financial, safety, or other high-stakes advice. Verify important information using appropriate qualified sources.
5. When we disclose information
We disclose information:
- To other EchoMind users according to your selected post audience, friendships, groups, direct-message recipients, reactions, and profile use.
- To configured hosting, database, storage, identity, push, AI, speech, scholarly-metadata, content-delivery, and optional paper-conversion or email providers to perform the requested Service.
- To protect users, investigate abuse, comply with law, or respond to valid legal process.
- As part of a merger, financing, acquisition, reorganization, or asset transfer, subject to applicable safeguards.
As a first-release business rule, EchoMind does not sell personal data, use it for cross-context behavioral advertising, combine it with third-party data for targeted advertising or advertising measurement, or disclose it to a data broker. Provider use outside EchoMind's instructions is not authorized.
6. Storage and retention
EchoMind stores account and Service records on its servers and stores selected settings, sessions, drafts, caches, synchronization state, and pending media on your device. iOS protects the native session in Keychain. Android uses app-private storage and disables Android backup. These measures do not establish encryption at rest for every local file, server, backup, or log.
We use the following retention criteria rather than one fixed period for every record:
- Account, profile, preference, AI, social, message, group, game, paper, conversion, search, memory, enhancement, and generated-audio records are kept while the account or source record remains active and as needed for continuity, synchronization, safety, and requested cache reuse. Supported item deletion removes the active item and its owned dependent records.
- Successful authenticated account deletion removes or de-identifies active account and account-owned records. A non-identifying inactive tombstone, content created by another person, and moderation evidence can remain where needed to preserve another person's record, prevent account-recreation races, investigate abuse, or comply with law.
- Session, OAuth-state, handoff, reset, processing-lease, and similar security records expire or are invalidated according to their bounded function. Push tokens and device records remain until disabled, superseded, stale, unsubscribed, or removed with the account.
- Raw Agent attachments follow the 24-hour and terminal-task criteria described above. Bounded lifecycle, moderation, deletion-request, and security records remain only while reasonably needed for their purpose, dispute handling, abuse prevention, or a legal obligation.
- Backup, proxy, CDN, and processor copies expire under their operational schedules or provider terms. EchoMind does not promise immediate erasure from every backup or processor. If an erased backup is restored for disaster recovery, applicable deletion must be re-applied.
7. Your choices and rights
You can choose optional enhancement languages, change app and voice settings, select a post audience, delete your own posts and comments where controls are available, control notifications, clear local private data, and log out. The language-assistant conversation control deletes its messages and retires its conversation shell. The Agent conversation control archives a thread and retains its audit trail. OnlyIdeas does not provide a first-release per-paper or per-history deletion control. Clearing local data or uninstalling the app does not delete server records.
You can initiate authenticated account deletion in native Settings. Signed-out request access is available on the Account Deletion page. Authenticated deletion requires the exact signed-in username and takes effect only after the server reports success. A signed-out request enters a private manual queue and is completed only after an authorized reviewer verifies control of the email already attached to the account; submitting the form does not prove ownership or confirm that an account exists.
Depending on applicable law, you may request access, correction, a portable copy, restriction, objection, consent withdrawal, or deletion by using the available product control or contacting echomind@lazying.art. EchoMind can ask for information reasonably needed to verify the request against the account and can deny or limit a request where law permits. Do not send an identity document or date of birth unless EchoMind specifically establishes a lawful need and secure channel.
8. Security
Production app traffic is configured for HTTPS and WSS, password credentials are stored using bcrypt hashes, Apple revocation credentials are encrypted, the iOS session is stored in Keychain, Android uses app-private storage with backup disabled, and server routes apply sessions and permissions. Private Agent attachments are kept outside the public upload tree and use bounded, file-first cleanup. No security method is perfect. EchoMind does not claim universal encryption at rest, an independently certified security program, or immediate deletion from every backup or provider.
9. Children
EchoMind includes AI and user-to-user communication and is not directed to children. The first release requires users to be 18 or older and to confirm that requirement during registration. EchoMind does not ask for or collect a date of birth for this eligibility check and does not offer a parental-consent path. If EchoMind learns that an ineligible person supplied personal data, it can restrict the account and delete or de-identify the data, subject to safety and legal retention. A younger audience or newly supported territory requires a separate age, notice, consent, and store-rating review before launch.
10. International transfers
LazyingArt LLC is a United States company. EchoMind and its configured recipients can process information outside your territory, where privacy laws may differ. A store-territory decision does not mean data stays in that territory. EchoMind will not claim participation in a transfer framework, standard contractual clauses, an adequacy decision, or a provider region unless the applicable evidence establishes it. A feature or territory without a required transfer mechanism must remain unavailable.
11. Changes to this Policy
We can update this Policy as the Service and legal requirements change. We will post the updated effective date and provide any notice or consent required by law. For a material change, EchoMind will use this page plus an in-app or account notice reasonably capable of reaching affected users before the change takes effect, and will request new consent when law requires it.
12. Contact
Questions, privacy requests, and safety reports can be sent to echomind@lazying.art or submitted through the Support page.
The public organization contact is LazyingArt LLC, 25 1ST Ave SW Ste A, Watertown, SD 57201-3507, United States. Public developer phone: +852 5624 5237. These contacts are not represented as a locally appointed representative or data-protection officer.