EchoMind public information

Privacy Policy

This Policy explains how EchoMind handles personal data when you use its mobile apps, website, AI and language tools, social features, games, notifications, and OnlyIdeas paper workspace.

Effective date 2026-09-24

1. Scope

LazyingArt LLC operates EchoMind ("EchoMind," "we," "us," or "our"). This Policy applies to personal data handled through the EchoMind mobile applications, website, AI and language tools, social features, games, notifications, and OnlyIdeas paper workspace (together, the "Service").

The native iOS app is sold as a one-time paid download through the App Store; the Android app is free on Google Play. Supported app versions can offer optional, auto-renewable AI Agent subscriptions through Apple or Google when available in your store. Everyday chat, posts, and language enhancement do not require an Agent subscription. Native purchase screens use the platform's billing system.

2. Information we collect

Account information

We collect a username, email address, password credential, invitation information, account status, and authentication records. Passwords used for password registration are stored as hashes rather than readable text. If you choose Google or Apple sign-in, we receive a provider-specific account identifier, verified email, optional profile name, and authentication metadata. For Apple accounts, EchoMind can retain an encrypted revocation credential so account deletion can revoke the provider authorization. You may also provide a first name, last name, avatar, language preferences, voice preferences, and other settings.

If the optional website wallet invitation is available and you choose it, we verify a signed message and link your public Ethereum address and verification time to your new account. We do not request your seed phrase or private key, send transactions, check your balance, or grant an airdrop. Browser-bound verification attempts expire after a short period and are cleaned up during later verification activity. The account-linked address is removed when you delete your account. Your chosen wallet provider handles its own connection and signing interface.

Language-assistant conversations and AI content

We process prompts, messages, AI responses, conversation metadata, optional memory items, selected language enhancements, voice-model choices, generated audio, and processing status for the language-oriented AI chat. AI output and language enhancements may be inaccurate.

Standalone AI Agent conversations and tasks

The separate AI Agent workspace stores its own conversation titles, messages, selected mode and naming preference, task requests and results, status and error records, model routing, usage or quota records, provider attempts, sources, and timestamps. These records support requested chat or research work, recovery, cancellation, and synchronization; they are not the language-assistant conversation history.

Standalone AI Agent attachments

When you select an image, PDF, audio file, or supported text document for an Agent turn, we process its filename, type, size, hash, private storage reference, bounded extracted or normalized content, thread, task, and message relationships, processing leases, lifecycle state, and cleanup timestamps. Raw attachment payloads are kept outside the public upload tree. Unattached or unfinished payloads become eligible for cleanup after 24 hours, and raw payloads attached to a task are scheduled for file-first cleanup when that task reaches a terminal result. Bounded lifecycle records and task content can remain with an archived Agent thread until account deletion. Archiving a conversation is not the same as deleting it. Backup and downstream-provider copies can follow different expiry schedules.

Voice and media

If you choose voice, attachment, avatar, camera, QR, or paper features, we process the audio, transcript, image, file, or PDF you select, together with file metadata and generated or converted content.

Social and communications data

We store posts, comments, visibility, reactions, follows, friendships, direct messages, group membership and messages, images, voice messages, edits, read state, invitations, blocks, and moderation reports needed to provide those features. Other users can receive or view content based on the audience you select and the relevant group or conversation membership.

Research workspace data

OnlyIdeas can process uploaded papers, filenames, file hashes, selected page ranges, structured transcriptions, scholarly search queries and results, search history, paper briefs, and paper-grounded discussion. When standalone Agent public-web research is enabled and requested, its research query, returned sources, and generated result are also processed as Agent and search activity. Do not upload material you lack permission to process or disclose.

Device, notification, and usage data

We process device and app identifiers, platform and app version, push tokens and endpoints, notification and sync state, feature usage counts, game activity and results, timestamps, user agent, and diagnostic or security records. Network, hosting, proxy, CDN, and configured provider operators can receive an IP address and ordinary request headers. EchoMind records request or task identifiers, errors, timing, and security events. The first native release contains no dedicated advertising or general-purpose analytics SDK.

Transaction data

Apple and Google process native purchases under their own terms and privacy policies. EchoMind receives purchase and subscription records, never your card or bank details. To verify purchases, restore access, and handle renewals, cancellations, and refunds, we associate a purchase with an opaque EchoMind account identifier and store the provider, product, subscription status, expiry time, verification time, and encrypted purchase reference. Signed provider notifications are processed in a bounded queue. These records are used for account access, billing support, fraud prevention, and reconciliation, not advertising or tracking.

Where website subscriptions are available, Stripe hosts checkout and payment management. Stripe processes the payment information you enter; EchoMind does not store your full card or bank details. EchoMind receives the customer and subscription identifiers, selected plan, payment status, and renewal information needed to maintain your account access. Availability and the recurring price are shown before purchase.

3. How we use information

We use the information described above to:

  • Create, authenticate, secure, and support accounts.
  • Provide AI chat, optional language enhancements, voice features, social communication, games, notifications, synchronization, and OnlyIdeas.
  • Preserve drafts, deliver queued content, and recover from interrupted connections.
  • Personalize language, voice, display, and optional memory behavior.
  • Enforce usage limits, prevent abuse, investigate reports, and protect users.
  • Verify optional purchases, restore paid access, and reconcile subscription renewals, cancellations, and refunds.
  • Send confirmation, password-reset, service, and security communications when email delivery is configured.
  • Operate, diagnose, and improve reliability.
  • Meet legal obligations and enforce our terms.

Where a jurisdiction requires a legal basis, EchoMind relies on performance of the user agreement to create an account and provide requested features; the user's affirmative feature choice or device permission for optional media, voice, notification, AI, and public-sharing actions; LazyingArt LLC's legitimate interests in securing, operating, debugging, moderating, and preventing abuse of the Service where those interests are not overridden by the user's rights; and compliance with legal obligations or valid legal process. Where consent is required, it can be withdrawn for future processing through the relevant setting or by contacting EchoMind. A feature will not be offered in a territory where its required basis or notice has not been established.

4. AI and automated processing

EchoMind's defining features are produced with AI services: language enhancements (ruby, grammar colors, pronunciation, explanations and translations), Language Assistant replies, the standalone AI Agent, voice transcripts, generated speech, and OnlyIdeas paper research. This section states exactly what is sent, who receives it, why, and how you control it. It applies to the iOS, Android, watch and web versions of the Service.

What is sent

  • Text you write or send for an AI feature: messages to the Language Assistant and the AI Agent; posts, comments, direct messages and group messages that you choose to enhance, together with the enhancement languages you selected; and optional memory items you saved for the assistant.
  • Voice: audio you record for voice messages or transcription, and the resulting transcripts.
  • EchoTalk calls: what you say or type during an EchoTalk call between two friends. Your device's dictation turns speech into text; that text is translated live into your friend's language, the settled utterances are kept as the call transcript with their translations, and when the call ends one summary of the transcript is generated and posted into the conversation.
  • Files: images, PDFs, audio and text documents you attach to an AI Agent turn, and papers you upload to OnlyIdeas, including bounded extracted text and page ranges.
  • Language games: when you start a language game from a direct message or a group, sentences and words from that conversation, so the practice round is built from your own material.
  • Request context: the feature, language, model and voice choices needed to fulfil the request, and a request identifier.

Your password, email address, sign-in credentials and contact list are never sent to AI providers. Content that you do not submit to an AI feature (for example a post you did not enhance) is not sent.

Who receives it

  • LazyingArt LLC (the EchoMind servers) receives everything first, stores your conversations, enhancements, transcripts and results with your account, and relays only the selected data to the providers below.
  • OpenAI, L.L.C. (United States) generates language enhancements, assistant replies, EchoTalk live translations and call summaries from the text above through the OpenAI API. See the OpenAI privacy policy and API data usage policies.
  • Hangzhou DeepSeek Artificial Intelligence Co., Ltd. (China) generates language enhancements, AI Agent replies, EchoTalk live translations and call summaries from the text and attachments above through the DeepSeek API. See the DeepSeek privacy policy.
  • Speech services operated by LazyingArt perform speech-to-text (durable voice transcripts) and text-to-speech, including spoken EchoTalk translations, on infrastructure LazyingArt controls; no other AI company receives your audio.
  • Apple processes native dictation on iOS under Apple's terms, on-device when the language supports it. Android native dictation uses the speech recognizer built into your device under its platform terms.
  • Crossref receives scholarly search queries when you request paper metadata in OnlyIdeas.
  • Mathpix, Inc. receives the PDF file and selected page range when you request OnlyIdeas PDF conversion, and returns recognized text, formulas and images. The complete file is uploaded even when only some pages are selected for conversion. EchoMind sets improve_mathpix=false to opt out of recognition-improvement use. See the Mathpix privacy policy. New conversions require acceptance of the September 24, 2026 disclosure; reading an existing conversion does not upload the PDF again.

The deployed Service selects between the named model providers by feature and availability; it does not add an undisclosed provider. Internal sandboxes and loopback relays are execution boundaries, not additional recipients. If a provider is added or replaced, this section and the in-app disclosure are updated before it receives data.

Why and how it is used

The data is used only to produce the enhancement, reply, transcript, speech or research result you requested, to keep that result with your account so it does not have to be regenerated, and to enforce usage limits and prevent abuse. Each provider processes the data as our processor under its API terms and our instructions; provider use outside EchoMind's instructions is not authorized. EchoMind does not sell this data, use it for advertising, or combine it with third-party data for advertising. We do not claim zero retention, training opt-out or a particular processing region for a provider unless its API terms and our deployed configuration establish that fact; the provider documents linked above describe their retention and protections.

Each third party named above provides protection for this data that is the same as or equal to the protection described in this Policy. We share data only under API terms that bind the provider to act as our processor, to use the data only to return the result we requested and only on our documented instructions, to keep it confidential, to apply security measures appropriate to it, and not to sell it or use it for its own advertising. We do not authorize any other use, and we do not share your data with a provider whose terms do not meet this standard.

Your permission and control

The EchoMind iOS app shows this AI disclosure on every device where you sign in, before any content is sent, and sends content to AI providers only after you choose Agree and continue on that device. The app enforces that decision in its AI request transports, including retries and background work. A new device or a reinstall asks again. The decision is also stored with your account settings (disclosure version and time) and checked for native-app processing. You can review the disclosure and withdraw permission at any time in Settings › AI data processing; choosing Not now or withdrawing keeps you signed in: the app stops sending your content to AI services, everything that does not involve AI keeps working, and an AI feature asks again before it runs. Supported Android releases use the same account permission; older releases may need an update to show a revised notice. The web app currently uses its feature selections and the settings in section 7 rather than this native-app permission screen; manage its AI features separately. New PDF conversions on any client additionally require the current account disclosure covering Mathpix. Visitors and signed-out sessions can read public posts and cannot trigger AI processing. Where a newer disclosure version changes the data, recipients or purposes, the native app asks again.

Do not rely on AI output as professional medical, legal, financial, safety, or other high-stakes advice. Verify important information using appropriate qualified sources.

5. When we disclose information

We disclose information:

  • To other EchoMind users according to your selected post audience, friendships, groups, direct-message recipients, reactions, and profile use.
  • To configured hosting, database, storage, identity, push, AI, speech, scholarly-metadata, content-delivery, and optional paper-conversion or email providers to perform the requested Service.
  • To protect users, investigate abuse, comply with law, or respond to valid legal process.
  • As part of a merger, financing, acquisition, reorganization, or asset transfer, subject to applicable safeguards.

As a first-release business rule, EchoMind does not sell personal data, use it for cross-context behavioral advertising, combine it with third-party data for targeted advertising or advertising measurement, or disclose it to a data broker. Provider use outside EchoMind's instructions is not authorized.

6. Storage and retention

EchoMind stores account and Service records on its servers and stores selected settings, sessions, drafts, caches, synchronization state, and pending media on your device. iOS protects the native session in Keychain. Android uses app-private storage and disables Android backup. These measures do not establish encryption at rest for every local file, server, backup, or log.

We use the following retention criteria rather than one fixed period for every record:

  • Account, profile, preference, AI, social, message, group, game, paper, conversion, search, memory, enhancement, and generated-audio records are kept while the account or source record remains active and as needed for continuity, synchronization, safety, and requested cache reuse. Supported item deletion removes the active item and its owned dependent records.
  • Successful authenticated account deletion removes or de-identifies active account and account-owned records. A non-identifying inactive tombstone, content created by another person, and moderation evidence can remain where needed to preserve another person's record, prevent account-recreation races, investigate abuse, or comply with law.
  • Session, OAuth-state, handoff, reset, processing-lease, and similar security records expire or are invalidated according to their bounded function. Push tokens and device records remain until disabled, superseded, stale, unsubscribed, or removed with the account.
  • Raw Agent attachments follow the 24-hour and terminal-task criteria described above. Bounded lifecycle, moderation, deletion-request, and security records remain only while reasonably needed for their purpose, dispute handling, abuse prevention, or a legal obligation.
  • Backup, proxy, CDN, and processor copies expire under their operational schedules or provider terms. EchoMind does not promise immediate erasure from every backup or processor. If an erased backup is restored for disaster recovery, applicable deletion must be re-applied.

7. Your choices and rights

You can choose optional enhancement languages, change app and voice settings, select a post audience, delete your own posts and comments where controls are available, control notifications, clear local private data, and log out. The language-assistant conversation control deletes its messages and retires its conversation shell. The Agent conversation control archives a thread and retains its audit trail. OnlyIdeas does not provide a first-release per-paper or per-history deletion control. Clearing local data or uninstalling the app does not delete server records.

You can initiate authenticated account deletion in native Settings. Signed-out request access is available on the Account Deletion page. Authenticated deletion requires the exact signed-in username and takes effect only after the server reports success. A signed-out request enters a private manual queue and is completed only after an authorized reviewer verifies control of the email already attached to the account; submitting the form does not prove ownership or confirm that an account exists.

Depending on applicable law, you may request access, correction, a portable copy, restriction, objection, consent withdrawal, or deletion by using the available product control or contacting echomind@lazying.art. EchoMind can ask for information reasonably needed to verify the request against the account and can deny or limit a request where law permits. Do not send an identity document or date of birth unless EchoMind specifically establishes a lawful need and secure channel.

8. Security

Production app traffic is configured for HTTPS and WSS, password credentials are stored using bcrypt hashes, Apple revocation credentials are encrypted, the iOS session is stored in Keychain, Android uses app-private storage with backup disabled, and server routes apply sessions and permissions. Private Agent attachments are kept outside the public upload tree and use bounded, file-first cleanup. No security method is perfect. EchoMind does not claim universal encryption at rest, an independently certified security program, or immediate deletion from every backup or provider.

9. Children

EchoMind includes AI and user-to-user communication and is not directed to children. The first release requires users to be 18 or older and to confirm that requirement during registration. EchoMind does not ask for or collect a date of birth for this eligibility check and does not offer a parental-consent path. If EchoMind learns that an ineligible person supplied personal data, it can restrict the account and delete or de-identify the data, subject to safety and legal retention. A younger audience or newly supported territory requires a separate age, notice, consent, and store-rating review before launch.

10. International transfers

LazyingArt LLC is a United States company. EchoMind and its configured recipients can process information outside your territory, where privacy laws may differ. A store-territory decision does not mean data stays in that territory. EchoMind will not claim participation in a transfer framework, standard contractual clauses, an adequacy decision, or a provider region unless the applicable evidence establishes it. A feature or territory without a required transfer mechanism must remain unavailable.

11. Changes to this Policy

We can update this Policy as the Service and legal requirements change. We will post the updated effective date and provide any notice or consent required by law. For a material change, EchoMind will use this page plus an in-app or account notice reasonably capable of reaching affected users before the change takes effect, and will request new consent when law requires it.

12. Contact

Questions, privacy requests, and safety reports can be sent to echomind@lazying.art or submitted through the Support page.

The public organization contact is LazyingArt LLC, 25 1ST Ave SW Ste A, Watertown, SD 57201-3507, United States. Public developer phone: +852 5624 5237. These contacts are not represented as a locally appointed representative or data-protection officer.

In-product reporting and blocking tools are available for privacy and safety concerns. Support and account-deletion information remain available without signing in.