Skip to content

Privacy Policy

Effective date: August 24, 2026

EchoThread does not sell reader data, run ads on the embed widget, or use cross-site tracking on commenters. We collect only the account, site, and comment data needed to operate the service, moderate discussions, prevent abuse, and support exports or deletion requests. On our own website — echothread.io, including the pages you see once you sign in — we do measure how visitors move through sign-up and checkout, using first-party analytics that are never attached to your account. Section 3.3 sets out exactly what that records and how to switch it off.

1. Introduction

EchoThread ("we", "us", "our") operates the echothread.io website, the EchoThread embeddable comment widget, and related services (collectively, the "Service"). This Privacy Policy explains what personal data we collect, how we use it, and your rights regarding that data. Your use of the Service is also governed by our Terms of Service.

By using the Service you agree to the collection and use of information in accordance with this policy. If you do not agree, please do not use the Service.

2. Data controller

EchoThread is operated by VectraSEO LLC, a Pennsylvania limited liability company, which is the data controller for the personal data processed through the Service. For questions about this policy or your data, contact us at privacy@echothread.io.

3. Data we collect

3.1 Site owners (dashboard users)

  • Account information: email address, display name, optional bio and avatar URL.
  • Site configuration: site name, domain, shortname, moderation preferences.
  • Authentication data: one-time magic link tokens (automatically deleted after use or expiry).

3.2 Commenters (embed widget users)

  • Authenticated commenters: email address, display name, and avatar (via Google, GitHub, X, or Facebook OAuth).
  • Imported or legacy guest commenters: optional guest name and email when present in migrated discussion data.
  • Comment content: comment text, uploaded images, and link preview metadata.
  • Technical data: IP address and user-agent string, collected with each comment submission.
  • Reactions: vote/reaction type associated with your user ID.

3.3 Our own analytics on echothread.io

We measure how people move through our own website so we can tell which pages and channels actually lead to a working installation. This applies to echothread.io — the public pages and, once you sign in, your dashboard. It does not apply to the embed widget: nothing described here runs on your site, or on the sites where people read and post your comments.

  • First-touch attribution stored in your browser: we keep utm_source, utm_medium, utm_campaign, utm_content, utm_term, the host of the referring site, and the landing path in your browser's localStorage for up to 90 days, so that if you sign up later we can attribute the signup to its source. This data lives only in your browser until/unless you create an account.
  • First-party funnel analytics: we record named steps — for example "landing", "viewed pricing", "started checkout", "created a site", "copied the snippet" — to our own servers. No third-party analytics service and no advertising network is involved. Each step records the step name, the page path you were on, a random visitor id generated in your browser, the attribution fields above, and — on checkout steps — which plan and billing period you were looking at.
  • These steps are not connected to your account. The request that sends them carries no sign-in credentials, and our server does not look up who you are when it receives one. No email address, name, user id or IP address is recorded on them, and identifiers that appear in dashboard web addresses (such as the id of one of your sites) are removed in your browser before the step is sent. That holds whether you are signed out or signed in.
  • How long we keep them: each step is deleted automatically 13 months after it is recorded. The random visitor id itself stays in your browser until you clear your browser storage or opt out; we do not give it an expiry date, and it is used only to place your own steps in order.
  • How to switch it off: we honour Global Privacy Control. If your browser or an extension sends that signal we record nothing at all and store no visitor id, and you do not need to ask us. We do not treat the older Do Not Track header as an objection: it is unmaintained and switched on by default in some browsers, so it does not tell us what you actually want. You can also clear your browser storage at any time, or write to privacy@echothread.io and we will act on it. The Service works exactly the same either way.

3.4 Feedback and the public roadmap

  • Feedback you send us: when you submit feedback from within the Service, we receive your message along with the email address on your account so we can follow up. Feedback is delivered to our team by email; your name and email stay private.
  • Feature requests on the public roadmap: we maintain a public product roadmap at echothread.io/roadmap. Roadmap items are curated by us — feature requests you submit are reviewed by our team and are not published automatically, and we do not display your name or email alongside a roadmap item.
  • Roadmap votes: when you upvote a roadmap item, we store your user ID, the item, and a timestamp so each signed-in account is counted once. Only the aggregate vote count is shown publicly; we never display who voted.

3.5 Data we do NOT collect

  • We do not load third-party cookies, analytics, or trackers on the embed widget or commenter-facing pages.
  • We do not serve advertisements or share data with ad networks.
  • We do not sell your data.

4. How we use your data

  • Authentication: to verify your identity via magic link email, Google OAuth, GitHub OAuth, or a passkey (WebAuthn). If you register a passkey, we store the resulting public-key credential and its identifier to let you sign in; we never receive your biometric data, which stays on your device.
  • Service delivery: to display comments, manage sites, and deliver notifications.
  • Moderation: IP addresses and user-agent strings help site owners manage spam and abuse.
  • Service and notification emails: to send magic link sign-in emails and account/security messages, to notify you when someone replies to your comment (on by default), and to send an optional weekly digest of your unread notifications (off by default). You can turn reply notifications and the digest on or off at any time from your notification preferences in the dashboard; every notification email also links to those settings. We do not send marketing or promotional emails.
  • Measuring our own funnel: to see how many visitors to echothread.io go on to create an account, install the widget, and subscribe, and which pages and channels those visitors arrived from, so we know what to improve. This uses the first-party analytics described in §3.3, which are not linked to your account, and reaches us only as counts and conversion rates.
  • Spam detection: when a new comment is submitted, its text is sent to Siftfy, our machine-learning classifier operated by EchoThread, which returns a spam probability score. Siftfy receives the comment text and minimal context; it does not receive your email, IP, or browser identifiers. See §6 for Siftfy's role as a sub-processor. We additionally apply local heuristics (keyword and pattern scoring) on the server.

5. Legal basis for processing (GDPR)

If you are in the European Economic Area (EEA), United Kingdom, or Switzerland, we process your personal data on the following legal bases:

  • Contract performance: processing necessary to provide the Service you signed up for (e.g., account creation, comment posting).
  • Legitimate interest: spam prevention, security, service improvement, and the first-party analytics on our own website described in §3.3, balanced against your rights. You may object to the analytics at any time and you do not have to give a reason — see §9.
  • Consent: where required by law, such as for optional data collection (e.g., guest email).

6. Third-party services and sub-processors

We use the following services to operate EchoThread:

  • Amazon Web Services (AWS): database hosting (DynamoDB), email delivery (SES), and image storage (S3). Data is stored in the US East (N. Virginia) region. AWS Privacy Policy.
  • DigitalOcean: application hosting and container registry. DigitalOcean Privacy Policy.
  • CloudFront (AWS): content delivery for static assets and the embed widget.
  • Siftfy (operated by EchoThread): machine-learning spam classifier that receives the text of each newly-submitted comment and returns a spam probability. Hosted in the same AWS region; does not receive email, IP, or browser identifiers.
  • Stripe: subscription billing for paid plans. Stripe receives the data needed to process payments (name, billing address, card details handled directly by Stripe). Stripe Privacy Policy.
  • Google OAuth: used for commenter authentication in the embed widget and for site-owner sign-in to the dashboard. When you sign in with Google we receive your email, name, and profile picture.
  • GitHub OAuth: used for commenter authentication in the embed widget. When you sign in with GitHub, we receive your verified primary email, display name, username, and avatar. GitHub Privacy Statement.
  • X (Twitter) OAuth: used for commenter authentication in the embed widget. When you sign in with X, we receive your X user ID, name, and username. X may not share an email address; when it does not, we generate a non-deliverable placeholder address so your sign-in still works. X Privacy Policy.
  • Facebook (Meta) OAuth: used for commenter authentication in the embed widget. When you sign in with Facebook, we receive your Facebook user ID, name, and profile picture. Facebook may not share an email address; when it does not, we generate a non-deliverable placeholder address so your sign-in still works. Meta Privacy Policy.

We do not sell, rent, or share your personal data with any other third parties.

7. International data transfers

Your data is stored and processed in the United States. If you are located outside the US, your data will be transferred to and processed in the US. We rely on the following safeguards:

  • AWS participates in the EU-US Data Privacy Framework.
  • Standard contractual clauses (SCCs) where applicable.

8. Data retention

  • Magic link tokens: automatically deleted after 15 minutes or upon use.
  • Account data: retained for as long as your account is active. You may request deletion at any time.
  • Comments: retained for as long as the associated site exists, unless deleted by the commenter or site owner.
  • Uploaded images: retained for as long as the associated comment exists.
  • Funnel analytics steps (§3.3): deleted automatically 13 months after each step is recorded. They are not connected to your account, so closing your account does not delete them — there is nothing on them that identifies you — and they expire on their own schedule.
  • First-touch attribution in your browser: up to 90 days, after which your browser discards it.

9. Your rights

Depending on your location, you may have some or all of the following rights:

GDPR (EEA, UK, Switzerland)

  • Access: request a copy of the personal data we hold about you.
  • Rectification: correct inaccurate or incomplete data.
  • Erasure: request deletion of your personal data ("right to be forgotten").
  • Restriction: request that we limit processing of your data.
  • Portability: receive your data in a structured, machine-readable format.
  • Objection: object to processing based on legitimate interest. For the analytics in §3.3 you can exercise this yourself, and immediately, by sending Global Privacy Control from your browser; you can also write to us.
  • Withdraw consent: where processing is based on consent, you may withdraw it at any time.
  • You also have the right to lodge a complaint with your local data protection authority.

CCPA / CPRA (California)

  • Right to know: what personal information we collect, use, and disclose.
  • Right to delete: request deletion of your personal information.
  • Right to opt out: we do not sell or share personal information for cross-context behavioral advertising.
  • Non-discrimination: we will not discriminate against you for exercising your rights.

LGPD (Brazil)

  • You have rights to confirmation, access, correction, anonymization, portability, deletion, and information about sharing with third parties.

PIPEDA (Canada)

  • You have the right to access and challenge the accuracy of your personal information held by us.

To exercise any of these rights, contact us at privacy@echothread.io. We will respond within 30 days (or sooner where required by law).

10. Cookies and local storage

EchoThread does not set first-party cookies. We use your browser's local storage for:

  • Authentication tokens (JWT) to keep you signed in. Removed when you log out.
  • Marketing attribution on echothread.io: utm_source, utm_medium, utm_campaign, utm_content, utm_term, referring host, and landing path, kept for up to 90 days and used only to attribute a later sign-up. Stays in your browser until/unless you create an account.
  • Funnel-analytics visitor id on echothread.io: a random identifier used to place your own steps on our site in order (§3.3). It is first-party — sent only to our servers, never to a third-party tracker — is not tied to any cross-site identity, and is not linked to your account. It has no expiry date and stays until you clear it or opt out.

The authentication token is strictly necessary to provide the Service. The marketing-attribution and funnel-analytics items are not strictly necessary. They are set across echothread.io — on the public pages and on your dashboard once you sign in — and are never loaded on the embed widget or commenter-facing pages, so the people who read and post comments on your site never receive them. We do not use them for advertising or cross-site tracking. You can remove all of these items at any time by clearing local storage in your browser settings, or refuse them from the outset by sending Global Privacy Control (§3.3); the Service remains fully usable without the non-essential items.

11. Children's privacy

The Service is not directed to children under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us at privacy@echothread.io and we will promptly delete it.

12. Security

We implement appropriate technical and organizational measures to protect your personal data, including:

  • Passwordless authentication (magic links, OAuth, and passkeys) to eliminate password-related breaches.
  • HTTPS encryption for all data in transit.
  • Encrypted storage at rest via AWS managed encryption.
  • Short-lived authentication tokens with automatic expiry.

No method of transmission or storage is 100% secure. If you become aware of a security vulnerability, please report it to security@echothread.io.

13. Staff access to your account

To resolve a support request we sometimes need to see your dashboard the way you see it — a moderation queue that looks empty, a widget that renders wrong, a usage figure you believe is mistaken. Rather than ask you for screenshots, an authorised EchoThread staff member can open a read-only support view of your account. This is what that means in practice:

  • When. Only to investigate a support, billing, abuse or security matter, and only by a named member of staff on our internal operator list. It is not used for marketing, analytics, or browsing.
  • Read-only. Staff cannot change anything. They cannot post, moderate, delete, alter a setting, change a plan, or act on your behalf in any way. The restriction is enforced by our systems, not by policy alone: a support session is technically incapable of making a change.
  • No credentials. Staff never see your API keys, SSO signing secrets, webhook secrets, personal access tokens, or payment identifiers. These are withheld from every screen in support view — staff can see that a key exists, never what it is.
  • Recorded, not announced. We do not send you a notification each time a session is opened. Every session is instead recorded internally: who opened it, which account, the reason they gave, and every screen they viewed. If you want to know whether your account has been viewed and what was seen, ask us and we will tell you from that record.
  • How long. Sessions are limited to 30 minutes and end automatically. The record of the session is kept for 400 days and then deleted.

If you would prefer we ask before ever opening a support view of your account, write to privacy@echothread.io and we will note it on your account.

14. Changes to this policy

We may update this Privacy Policy from time to time. We will post the updated policy on this page with a revised effective date, and for material changes we will provide reasonable advance notice — for example, by email to the address on your account or by a notice on the Service — before the change takes effect. Where the law requires your consent for a new or changed use of your personal data, we will obtain that consent rather than rely on your continued use.

15. Contact us

If you have any questions about this Privacy Policy or our data practices, contact us at:

privacy@echothread.io

EchoThread EchoThread
Terms of Service© 2026 EchoThread. Privacy-first comments for the modern web.

Updated