Your learning records are local by default, microphone audio is processed with Apple on-device speech recognition, and AI requests go directly to the provider you choose. Account, optional avatar, purchase, and optional iCloud features use the services described below.
Scope and privacy approach
This Privacy Policy covers SuperEcho for iPhone and the SuperEcho website. It does not replace the privacy policies of Apple, your chosen AI provider, Supabase, RevenueCat, or websites you open from our service.
- We do not sell personal information.
- We do not use third-party advertising SDKs.
- We do not use your conversations to train a SuperEcho AI model.
- The website uses only a language-preference cookie and currently has no behavioral analytics.
Because AI requests are sent directly from your device, the provider you choose—not SuperEcho—controls its own server-side processing of those requests.
Information we handle
The information involved depends on the features you choose. Some stays only on your device, while limited account and service data is handled by third parties that operate specific features.
- Account data: a Supabase user identifier and information Apple makes available during Sign in with Apple, which may include a relay email address and name.
- Profile data: an optional display name and optional profile photo.
- Learning data: conversation transcripts, practice answers, feedback, saved language, scenario progress, streaks, preferences, and related evidence.
- AI configuration: provider and model selections; API keys are stored in the iOS Keychain.
- Purchase data: product, entitlement, renewal, and transaction status supplied through Apple and RevenueCat, but not your full payment-card details.
- Website data: standard request information such as IP address, user agent, and requested page may be processed by hosting, CDN, and font-delivery providers.
Do not place confidential personal, health, financial, or workplace information into a practice conversation unless it is genuinely necessary and you accept the chosen provider’s handling of it.
Device permissions
SuperEcho asks for system permissions only when a feature needs them. You can deny or later change permissions in iOS Settings, although the related feature may stop working.
- Microphone and Speech Recognition: record an attempt and create an on-device transcript.
- Camera and Photos: use only the photo you capture or select for Picture Speaking or a profile image.
- Notifications: deliver practice, streak, course, or other reminders you enable.
- Screen Time / Family Controls: apply an optional focus policy to the apps and categories you select using Apple-managed authorization and device-side controls.
SuperEcho does not continuously record audio or browse your entire photo library. Access occurs through Apple’s permission and picker interfaces.
Voice, AI, and image processing
SuperEcho requests Apple on-device speech recognition for dictation, so microphone audio is not sent to an AI provider for transcription. The resulting text is sent from your device to your selected AI provider when you ask for conversation, feedback, analysis, or generated practice.
- Requests may include your current text, recent conversation context, learning goal, proficiency context, and instructions needed to generate useful feedback.
- For Picture Speaking, image analysis can stay on device with Apple Vision or, if you deliberately choose a supported cloud vision mode, the selected image is sent directly to that provider.
- Text-to-speech normally uses Apple system voices; remote media linked in provider output may be fetched when displayed or played.
- Provider requests use an ephemeral network session without persistent HTTP cookies or response caching.
Review the selected provider’s policy before connecting it. Provider retention, model training choices, security, international transfers, and deletion rights are governed by that provider.
Where data is stored
Learning history is stored locally on your device. If you enable private learning sync, an archive is stored in your private iCloud / CloudKit database so it can be restored and synchronized across your Apple devices.
- AI API keys are stored in the iOS Keychain.
- Supabase stores authentication records and, if you add one, your profile photo.
- RevenueCat stores the purchase and entitlement information needed to recognize SuperEcho Pro access.
- App-group storage may hold streak and optional Screen Time settings shared with SuperEcho extensions.
- Local caches may contain course assets, avatar thumbnails, and other data needed for performance.
Signing out does not by itself remove all local, iCloud, Supabase, RevenueCat, Apple, or AI-provider records.
Services involved
SuperEcho relies on a small set of processors and platforms for features you choose. Each processes information under its own privacy terms and security practices.
- Apple: Sign in with Apple, Speech, Vision, iCloud / CloudKit, notifications, Screen Time controls, App Store purchases, and device services.
- Supabase: authentication and optional avatar storage.
- RevenueCat: product offerings, purchase restoration, subscription status, and entitlement verification.
- DeepSeek, MiniMax, LongCat, or OpenRouter: only the AI provider you configure receives the AI requests you initiate.
- Website infrastructure and Google Fonts: delivery of the website, fonts, and standard network requests.
OpenRouter may route a request to a model provider you select through its catalog; that additional provider may also process the request under the routing options you choose.
How information is used
We and our service providers use information only as needed to provide, secure, maintain, and improve the features described in this policy.
- Authenticate you and maintain your profile.
- Generate conversations, feedback, exercises, and progress evidence.
- Sync or restore learning data when you enable private iCloud sync.
- Deliver content, notifications, and optional focus controls.
- Verify purchases, restore access, and provide subscription support.
- Prevent abuse, diagnose failures, protect security, and comply with law.
- Remember your language choice on the website.
SuperEcho does not run an advertising profile or cross-app tracking system.
Retention and deletion
Retention depends on where data is stored and the feature involved. Local learning data remains until you delete it, reset it, or remove the App, subject to Apple backups. Private iCloud data remains under your iCloud account until removed or replaced through available controls.
- Hosted authentication and profile data is kept while your account is active and as needed for security, support, legal, and backup obligations.
- Purchase records may be retained by Apple and RevenueCat for tax, fraud-prevention, entitlement, and legal purposes.
- AI providers retain requests according to the provider and options you choose.
- The language cookie expires after approximately one year unless replaced or removed.
Deletion from active systems may not immediately remove limited backup, security, transaction, or legally required records.
Your choices and rights
Depending on your location, you may have rights to access, correct, delete, restrict, object to, or receive a copy of certain personal information. You also control many processing choices directly in the App and iOS.
- Change or revoke device permissions in iOS Settings.
- Choose, switch, or remove an AI provider and delete its Keychain credential.
- Enable or disable private iCloud learning sync and use available export or delete controls.
- Replace your optional profile photo, or request deletion through support.
- Manage or cancel subscriptions through Apple and restore purchases in SuperEcho.
- Clear the website language cookie in your browser.
- Request deletion of hosted account data through the official support channel.
We may need to verify your identity before fulfilling an account request. Your rights may vary, and lawful exceptions can apply.
Security
SuperEcho uses platform security features and scoped architecture, including iOS Keychain storage for API keys, Sign in with Apple, HTTPS connections, private iCloud databases, and provider requests made without persistent cookies or caches.
- No service can guarantee perfect security.
- Protect your device, Apple account, and AI-provider credentials.
- Do not send API keys, passwords, or recovery codes to support.
If you believe your account or data is at risk, revoke the affected credential and contact the relevant provider and SuperEcho support promptly.
Children
SuperEcho is not directed to children under 13, and we do not knowingly collect personal information from a child under 13. A higher minimum age may apply in some locations.
- A parent or guardian should supervise use by a minor.
- If you believe a child provided personal information without appropriate consent, contact us so we can review and delete it where required.
AI providers and App Store services may impose their own age requirements.
International processing
Apple, Supabase, RevenueCat, website infrastructure, and AI providers may process data in countries other than where you live. Data-protection laws can differ across those locations.
- The destination depends partly on the service region and AI provider you select.
- Service providers are responsible for the transfer mechanisms and safeguards described in their own policies.
Choose a provider and region appropriate for the sensitivity of your content and your legal requirements.
Changes to this policy
We may update this policy when SuperEcho adds features, changes providers, or legal requirements evolve. The effective date at the top identifies the current version.
- Material changes will be communicated through a reasonable channel, such as the App or website.
- Earlier versions may be retained for reference where practical.
Review this page periodically, especially after a major App update.
Contact and privacy requests
Privacy questions and requests can be sent through the App Support link on SuperEcho’s App Store listing. If a support email is configured for this website, it appears below.
- Describe the account and right you want to exercise without sending passwords or API keys.
- For data controlled by Apple or an AI provider, contact that provider directly as well.
We will respond within the period required by applicable law after any necessary identity verification.