Skip to content
Legal

Data & Compliance

A transparent look at how EchoFrame meets the GDPR, Apple App Store and Google Play privacy requirements — the principles, the providers, the retention periods and the security behind the product.

Effective
30 June 2026
Operator
Gioel Antoni (Italy)
Applies to
EchoFrame app & website
On this page

This document complements our Privacy Policy and Terms of Use. It sets out, in one place, how EchoFrame complies with modern privacy regulation and the requirements of the mobile app stores. It is written to be useful both to users who want detail and to reviewers assessing the Service.

1. GDPR — controller & processors

  • Data Controller: Gioel Antoni, an individual sole proprietor in Italy, decides why and how your data is processed. Contact: support@echoframe.help.
  • Data Processors: the providers that process data on our behalf and under our instructions (such as Supabase for hosting and MapTiler for maps). They are listed in the processor register below, each under a data-processing agreement.
  • Supervisory authority: as we are established in Italy, our lead authority is the Garante per la protezione dei dati personali.

2. GDPR — how we apply the principles

Purpose limitation

We collect data for the specific purposes set out in the Privacy Policy — running your account, anchoring and discovering echoes, social features and security — and we do not reuse it for unrelated purposes.

Data minimisation

We collect only what the Service needs. There are no advertising identifiers, no contacts access, no background movement log, and no analytics SDKs in the App. The location we store is the point you deliberately anchor an echo to.

Storage limitation

We keep data only as long as needed for the purpose it was collected, per the retention schedule. When you delete your account, your data is removed and ages out of backups.

Lawful basis

Every processing activity has a lawful basis — contract, consent, or legitimate interests — set out in the Privacy Policy. Sensitive processing (precise and background location) relies on your explicit device-level consent.

Privacy by design & by default

  • Camera-only capture means we never ingest your whole photo library.
  • Background location is off until you explicitly enable proximity alerts.
  • Each echo defaults to the visibility you choose, and private circles limit who can discover an echo within the App.
  • Database row-level security enforces, at the data layer, that users can only reach data they're entitled to.

3. Your rights & how to exercise them

The GDPR gives you the following rights. Here is exactly how to use each.

RightWhat it meansHow to exercise it
AccessGet a copy of your dataEmail support@echoframe.help from your account address
RectificationCorrect inaccurate dataEdit your username/avatar in the App, or email us
ErasureDelete your account & dataApp → Settings → Account → Delete account
RestrictionLimit how we process your dataEmail support@echoframe.help
ObjectionObject to legitimate-interest processingEmail support@echoframe.help
PortabilityReceive your data in a portable formatEmail support@echoframe.help
Withdraw consentTurn off location, notifications or emailsDevice settings (permissions); unsubscribe link (emails)
ComplainLodge a complaint with a regulatorGarante per la protezione dei dati personali (Italy) or your local authority

We aim to respond to any request within one month, as the GDPR requires.

4. Apple App Store compliance

Our App Privacy information on the App Store reflects the practices in this document. In summary:

  • Data linked to you: contact info (email), user content (photos, comments, messages), identifiers (account ID) and precise location — all used only to run the Service.
  • Tracking: we do not track you across other companies' apps or websites, and we do not use data for third-party advertising.
  • Permission strings: the App explains, at the moment it asks, why it needs the camera, location (while-in-use and background) and notifications.
  • Background location: requested only for proximity alerts, with a clear in-app explanation before the system prompt.
  • Account deletion in-app: as required by App Store guidelines, you can delete your account and all associated data directly in the App (Settings → Account → Delete account).

5. Google Play Data Safety

What we declare in the Play Console Data Safety form.

Data typePurposeRequired / OptionalShared?
Email addressAccount management, app functionalityRequiredNo
UsernameApp functionality (shown to other users)RequiredNo
Photos (echoes & avatar)App functionality — core contentRequired to postNo
Precise locationApp functionality — anchor & discover echoesRequired (foreground)To map provider, to render maps
Background locationProximity ('echo nearby') alertsOptionalNo
MessagesApp functionality — direct messagesOptionalNo
Other UGC (comments, ratings)App functionalityOptionalNo
Device push tokenApp functionality — deliver notificationsOptionalTo Expo and Google FCM, to deliver them
Notification preferences & device time offsetApp functionality — apply your quiet hours and per-type choices while the App is closedOptionalNo
Other app preferences & activityApp functionality (stored on device)OptionalNo
‘Shared’ means transfer to a third party. Providers that process data only on our behalf (e.g. Supabase) are processors, not third-party sharing. Data is encrypted in transit; account deletion is available in-app and via our website.

6. Security

  • Encryption in transit: all communication uses HTTPS/TLS.
  • Encryption at rest: databases and stored files are encrypted at rest by our infrastructure providers.
  • Password handling: passwords are salted and hashed (bcrypt) by our authentication provider; we never store or see plaintext passwords.
  • Authentication security: sessions use short-lived, auto-refreshing tokens stored in your device's hardware-backed secure storage; authentication endpoints are rate-limited by our provider.
  • API & access control: database row-level security policies enforce per-user access at the data layer; storage access is scoped to each user's own files.
  • Backups: encrypted backups support recovery and are rotated on a rolling window.
  • Logging: we keep limited operational logs for security and debugging, and avoid logging sensitive personal data in production.

We continuously work to improve our security posture as EchoFrame moves from beta to public launch, including hardening storage access and formalising our incident-response process.

7. Third-party processor register

Every external service that touches data, what it does, and its role.

ServicePurposeData sharedPrivacy policyGDPR role
SupabaseAuthentication, database, file storage, account emailsAccount, photos, location, social content, messagessupabase.com/privacyProcessor (hosts in the UK)
MapTilerMap tiles / basemapsIP address, map area viewedmaptiler.com/privacy-policyProcessor
MapLibre (demo tiles)Fallback map tiles when no MapTiler key is configuredIP address, map area viewedmaplibre.orgThird-party service
OpenStreetMap (Overpass)Reverse place-type lookupCoordinates of the area being labelledosmfoundation.org/wiki/Privacy_PolicyThird-party service
VercelWebsite hosting, waitlist function, cookieless analyticsWaitlist email & optional city/country; aggregate trafficvercel.com/legal/privacy-policyProcessor
ResendSends the waitlist confirmation email (Website), and the moderation alert for every report (App)Email address; a report alert also carries the reporting and reported usernames, the reason, and the reporter's free-text descriptionresend.com/legal/privacy-policyProcessor
Expo (EAS & Push)Builds the App, and delivers its push notificationsDevice push token; the username and echo coordinates carried inside a proximity notificationexpo.dev/privacy-explainedProcessor
Google (FCM) · Apple (APNs)Carries a push notification the last hop to the device, for ExpoDevice push token; the username and echo coordinates inside a proximity notificationfirebase.google.com/support/privacy · apple.com/legal/privacySub-processors (engaged via Expo)
Apple / GoogleApp distribution & operating-system servicesDownload, device and (future) payment dataapple.com/legal/privacy · policies.google.com/privacyIndependent controllers

When optional paid features launch, a subscription-management provider (such as RevenueCat) and the app stores' payment systems will process purchase data. This register and the Privacy Policy will be updated before that happens.

8. Data retention schedule

Data categoryRetention period
Accounts (email, username, profile)Until you delete your account
Conversations (direct messages)Until deleted, or removed with your account
Uploaded files (echo photos, avatars)Until you delete them or your account
Analytics (Website)Aggregate & cookieless; no personal profile retained
Operational logsShort retention for security/debugging, then deleted
Authentication recordsRemoved when you delete your account
Encrypted backupsRolling window (~7 days), then overwritten
Waitlist email (Website)Until launch or unsubscribe

9. International data transfers

Core data is stored in the United Kingdom (London region), which benefits from a UK adequacy decision. Where a provider processes data in the United States or elsewhere, we rely on appropriate safeguards (Standard Contractual Clauses and, where applicable, the EU–US Data Privacy Framework). See the Privacy Policy for more.

10. Contact & updates

We review this document as the Service and the law evolve, and update the effective date on any material change. Questions or requests:

Questions about this document or your data? Contact us at support@echoframe.help.