Legal
Cookie Policy
Effective date: July 21, 2026
Get AI Explanation
Need help understanding this document? Get an AI-powered explanation from your favorite AI models.
This policy explains what cookies and similar technologies Echo IO, Inc. uses on echoio.ai and in the Echo application, why we use them, and the choices you have.
1. What Cookies Are
Cookies are small text files placed on your device by a website. Similar technologies include browser localStorage (key-value data stored by your browser) and pixels; we use the term "cookies" for all of these. Cookies can be "first-party" (set by us) or "third-party" (set by another company).
Everything described below is first-party: even our analytics traffic is routed through our own domain, and we do not use advertising or cross-site tracking cookies.
2. How We Use Cookies
- Strictly necessary — required for the site or application to function: signing you in, keeping your session secure, and remembering your cookie choice itself. These cannot be switched off.
- Attribution — a first-party cookie that records how you arrived at the site (referral source and UTM campaign parameters), used only to attribute pilot requests to their source. It involves no third-party calls, is never shared, and is only set if you accept measurement cookies.
- Measurement (analytics) — help us understand how the site and product are used so we can improve them. On our website these are off until you accept them (see "Your Choices").
We do not sell data collected by cookies.
3. Cookies on This Website (echoio.ai)
- Consent choice (localStorage) — strictly necessary. Remembers whether you accepted or declined measurement cookies. Kept until cleared.
- echo_attribution — attribution; set only after you accept measurement cookies, and deleted if you decline or withdraw. First-party record of your arrival source (referrer and UTMs), used only to attribute pilot requests. Kept up to 90 days.
- ph_*_posthog (cookie + localStorage) — measurement; set only after you accept. A random identifier used by PostHog product analytics to understand page views, feature interest, and errors, and, where enabled, to replay in-page interactions (session replay). Served first-party via our own domain. Kept up to 12 months.
- Vercel Web Analytics — measurement; loaded only after you accept. Cookieless: it measures aggregate page traffic without storing identifiers on your device.
Before you make a choice, no measurement tools run at all — PostHog is not initialized, Vercel Analytics is not loaded, and no attribution cookie is written until you opt in.
4. Cookies in the Echo Application
Signed-in users of the Echo platform additionally get:
- __Secure-better-auth.session_token — strictly necessary. Keeps you signed in to your account. Session lifetime.
- __Secure-better-auth.session_data — strictly necessary. Short-lived cache of session data to speed up the app. Minutes.
- OAuth state/PKCE cookies — strictly necessary. Protect account-connection flows (e.g., linking an ad or social account) against forgery. Duration of the connect flow.
- Theme and interface preferences (localStorage) — strictly necessary. Remembers interface preferences such as theme and dismissed notices. Until cleared.
- ph_*_posthog (cookie + localStorage) — measurement. PostHog product analytics, error diagnostics, and, where enabled, session replay for signed-in product usage. Kept up to 12 months.
5. Your Choices
When you first visit echoio.ai, a banner asks whether you accept cookies. Accept enables the measurement and attribution cookies described above; Reject (the X) keeps only strictly necessary cookies; Customize lets you decide per category. You can change your choice at any time via the "Cookie settings" link in the site footer.
If your browser sends a Global Privacy Control (GPC) signal and you have not yet made a choice, we honor it by saving a strictly-necessary-only decision: no measurement or attribution cookies are set and the banner will not ask again. You can still opt in explicitly afterwards via "Cookie settings".
Most browsers also let you block or delete cookies and localStorage via their settings. Blocking strictly necessary cookies may break sign-in and other core functionality of the application.
6. Changes & Contact
We may update this policy as our cookie use changes and will post updates here with a new effective date. Questions: legal@echoio.ai. See also our Privacy Policy at echoio.ai/privacy-policy.
Back to home