HyperEcho · Legal
Privacy Policy
Effective August 22, 2026
HyperEcho provides live AI-assisted spoken translation and optional voice matching. This policy explains what we process and the choices available to you.
Information we process
- Sign in with Apple and Supabase account identifiers, and an email address when Apple supplies one.
- Microphone audio, transcripts, translations, selected languages, and generated translated audio.
- Short voice samples and related transcripts when a participant expressly enables a temporary conversation voice or the app user creates My Voice.
- Verified App Store transactions, subscription state, and metered translation use.
- Feedback you submit. Conversation text is attached only when you turn on the separate sharing toggle; audio is never attached.
- Request IDs, app version, timestamps, status, duration, network/security information, and provider errors needed to operate and protect the service.
How we use and share it
We process information to authenticate accounts; transcribe, translate, and speak requested content; provide optional temporary or saved voice matching; meter credits; verify purchases; prevent abuse; delete data; respond to feedback; and operate the service. We do not sell data, run behavioral advertising, or use HyperEcho for cross-app tracking.
Third-party AI permission
Before live translation or voice features are available, HyperEcho names OpenAI and Fish Audio, explains the personal data sent to each, and asks the app user for explicit permission. Permission can be withdrawn in Settings. When one phone is shared, both people review the disclosure and explicitly agree before either microphone can open.
OpenAI processes microphone or requested voice-demo audio, selected languages, up to four recent transcript/translation turns, and a random per-conversation safety identifier for transcription and text/speech translation. Fish Audio processes translated text for generated speech and, only when voice matching is enabled, the chosen saved-voice profile name, short voice samples, their transcripts, and a provider-generated voice-model reference used for temporary or saved matched speech. Supabase provides authentication and database services. Railway hosts the API, private application storage, and operational logs. Apple provides sign-in, purchases, and subscription management. These processors may retain information under their own terms and may process it in countries where they operate.
Voice consent
Translation works with standard generated voices and does not require voice matching. When enabled in Settings and a reviewed consent language is selected, the other participant gets one explicit choice before the conversation. If they agree, HyperEcho learns a temporary matched voice from their turns; the agreement is limited to that conversation and is not restored from history. Creating My Voice is separately optional and requires one explicit agreement from the app user. Anyone authorizing a voice must be at least 16 and have the right to authorize it.
Retention and deletion
- Uploaded turn audio is removed from temporary server storage after its request finishes.
- To make a network retry safe, the completed turn response (transcript, translation, and generated translated audio) may remain in private server-only storage for up to one hour. It is used only to return the same result without repeating AI processing or usage charges.
- A temporary conversation voice is removed when the live session ends; provider deletion is retried after an outage.
- My Voice remains until you delete, replace, or delete your account.
- On-device history is on by default. It stores transcripts, each spoken turn's original microphone recording, and generated translated audio so you can replay both sides. It is protected, excluded from backup, capped, and removed after your selected 1-, 7-, or 30-day period. Turning history off deletes its saved content. A text-only export is shared only when you invoke the system share sheet and choose a destination; HyperEcho does not automatically upload that export.
- Account, purchase, usage, and security records remain only as needed to provide the service, keep an accurate ledger, prevent fraud, meet legal obligations, and resolve disputes.
Your controls
You can decline or withdraw third-party AI permission, decline microphone access, decline or disable temporary voice matching, use standard voices, delete My Voice, disable or clear local history, omit conversation text from feedback, sign out, and delete your account in Settings. Deleting HyperEcho does not cancel an Apple subscription. Apple may require a fresh sign-in so its token can be revoked during account deletion.
Children, security, and international use
HyperEcho is not directed to children under 13. Voice matching requires the authorizing person to be at least 16. We use TLS, restricted credentials, database access controls, protected on-device files, and encrypted Apple revocation credentials, but no system is risk-free. Data may be processed in the United States and other provider locations.
AI safety
AI translation can be incomplete or wrong. Do not rely on HyperEcho for emergencies or medical, legal, financial, or other safety-critical decisions. Confirm important information another way.
Contact and changes
Use HyperEcho Support or the in-app feedback form for privacy requests. We may update this policy as the service or law changes and will change the effective date.