Privacy Policy
Effective date: October 4, 2026
What data does EchoThread collect?
EchoThread collects only the account, site, and comment data needed to run the service, moderate discussions, prevent abuse, and honour export or deletion requests. We do not sell reader data, show ads in the widget, track commenters across sites, or run behavioural analytics. Visits to echothread.io leave page-request logs without IP addresses, deleted after 7 days, and a note in your browser of the campaign that referred you, which you can refuse.
1. Introduction
EchoThread ("we", "us", "our") operates the echothread.io website, the EchoThread embeddable comment widget, and related services (collectively, the "Service"). This Privacy Policy explains what personal data we collect, how we use it, and your rights regarding that data. Your use of the Service is also governed by our Terms of Service.
By using the Service you agree to the collection and use of information in accordance with this policy. If you do not agree, please do not use the Service.
2. Data controller
EchoThread is operated by VectraSEO LLC, a Pennsylvania limited liability company, which is the data controller for the personal data processed through the Service. For questions about this policy or your data, contact us at privacy@echothread.io.
3. Data we collect
3.1 Site owners (dashboard users)
- Account information: email address, display name, optional bio and avatar URL.
- Site configuration: site name, domain, shortname, moderation preferences.
- Authentication data: one-time magic link tokens (automatically deleted after use or expiry).
3.2 Commenters (embed widget users)
- Authenticated commenters: email address, display name, and avatar (via Google, GitHub, X, Facebook, or Discord OAuth). A commenter who signs in with Bluesky or Mastodon gives us their public handle and account identifier, not an email address; we keep the sign-in token sealed (encrypted) so that, when they choose, we can post their comment as a reply from their own account and delete that reply when they delete the comment.
- Replies imported from Bluesky or Mastodon: on sites whose owner links a page to a public Bluesky or Mastodon post, we copy the public replies to that post (the text, the author's public handle and profile link, and the time) so they appear under the page. We load no images from those networks, and a reply deleted there is removed here the next time we read the post.
- Imported or legacy guest commenters: optional guest name and email when present in migrated discussion data.
- Comment content: comment text and any star rating you attach, uploaded images, link preview metadata, and, when a commenter attaches a GIF, a link to that GIF and its title as supplied by KLIPY (we store the link, never the GIF file).
- Technical data: IP address and user-agent string, collected with each comment submission.
- Reactions: vote/reaction type associated with your user ID.
- Poll votes: on sites that run a reader poll, voting needs no account. We store which answer was chosen and a one-way hash of your IP address and browser user-agent, salted separately for each poll, so the same browser cannot vote twice and votes cannot be linked from one poll to another. The hash is never shown to the site owner or included in exports, and it is deleted 30 days after the poll closes, or immediately when the poll is deleted. Your browser also remembers your answer locally (§10).
3.3 What we record about visits to echothread.io
No analytics script runs on our website. We do not follow the steps you take through sign-up or checkout, and we do not give your browser an identifier that would let us recognise it from one visit to the next, so nothing we keep can link one of your visits to another. No third-party analytics service and no advertising network is involved anywhere on the site. None of this ever applied to the embed widget, and it still does not: nothing described here reaches the people who read and post comments on your site.
Two things remain: short-lived request logs on our side, and one item that stays in your browser.
- Request logs kept by our content delivery network: when your browser asks echothread.io for a page or file, Amazon CloudFront logs the address requested (including anything after the "?"), the date and time, the response status, the referring site, your country, your browser's user-agent string, and whether the response came from cache. It never logs your IP address or your cookies; your country is worked out by CloudFront from the connection, and the address it came from is not kept. These logs are deleted automatically after 7 days. Once a day we add them up into per-page totals — how many requests each page received, by response status, by kind of visitor (a person, a search engine, an AI crawler or another bot), by referring site, by the campaign tags
utm_source,utm_mediumandutm_campaign, and by country — and send only those totals to VectraSEO, the search-optimisation service we use for echothread.io (§6). Nothing else from the address leaves the logs, and a referring site, campaign or country seen fewer than three times in a day is counted under "other". The totals contain no IP address, cookie, user-agent string or visitor identifier. - First-touch attribution stored in your browser: we keep
utm_source,utm_medium,utm_campaign,utm_content,utm_term, the host of the referring site, and the landing path in your browser's localStorage for up to 90 days, so that if you sign up later we can attribute the signup to the campaign or link that brought you. It is written once, on your first visit, and is not updated as you move around the site. Nothing is sent to us while you are browsing: this data lives only in your browser, and reaches us only when you go on to create an account or start a sign-in — at which point it is attached to a newly created account and nothing else. If you sign in to an account that already exists, it is discarded. - How to refuse it: we honour Global Privacy Control. If your browser or an extension sends that signal we store nothing at all, and you do not need to ask us. We do not treat the older Do Not Track header as an objection: it is unmaintained and switched on by default in some browsers, so it does not tell us what you actually want. You can also clear your browser storage at any time, or write to privacy@echothread.io and we will act on it. The Service works exactly the same either way.
3.4 Feedback and the public roadmap
- Feedback you send us: when you submit feedback from the dashboard or from the comment widget while signed in, we receive your message, the optional mood and type you choose, and the email address on your account so we can follow up. We also record the context it was sent from — the page URL or dashboard screen, the site, and your browser's user-agent string — and, if you attach one, a screenshot. We store your feedback, its context and any screenshot so our team can track it and so you can see its status at echothread.io/account/feedback, and we deliver a copy to our team by email. Your name and email are never shown publicly. Feedback is never shared with site owners.
- Feature requests on the public roadmap: we maintain a public product roadmap at echothread.io/roadmap. Roadmap items are curated by us — feature requests you submit are reviewed by our team and are not published automatically, and we do not display your name or email alongside a roadmap item.
- Roadmap votes: when you upvote a roadmap item, we store your user ID, the item, and a timestamp so each signed-in account is counted once. Only the aggregate vote count is shown publicly; we never display who voted.
3.5 Data we do NOT collect
- We do not load third-party cookies, analytics, or trackers on the embed widget or commenter-facing pages. The one third party a reader's browser contacts from the widget is KLIPY, for GIF search and GIF images, as described in §6.
- We do not run behavioural analytics on echothread.io either: no analytics script, no visitor identifier in your browser, and the only record of page requests is the IP-free request log described in §3.3, deleted after 7 days.
- We do not serve advertisements or share data with ad networks.
- We do not sell your data.
3.6 Profiles and public profile pages
Any signed-in user can edit a display name, avatar, bio and website on their profile at echothread.io/profile. Your profile is private until you opt in to a public profile. Turning on "Public profile" and choosing a handle publishes a page at echothread.io/u/<handle> that anyone can open without signing in. That page shows exactly four things: your display name, your avatar, your bio and your website link. It never shows your email address or a list of your comments. The page asks search engines not to index it, and the website link is marked nofollow, ugc and noopener.
On sites whose owner offers Sign in with EchoThread, your name in a comment links to your public profile, but only if you have opted in. You can turn the public profile off or change your handle at any time and the old page stops working immediately. Deleting your account removes your uploaded avatar, releases your handle and removes the page. Accounts created through a publisher's single sign-on cannot edit or publish a profile.
4. How we use your data
- Authentication: to verify your identity via magic link email, Google OAuth, GitHub OAuth, or a passkey (WebAuthn). If you register a passkey, we store the resulting public-key credential and its identifier to let you sign in; we never receive your biometric data, which stays on your device.
- Service delivery: to display comments, manage sites, and deliver notifications.
- Moderation: IP addresses and user-agent strings help site owners manage spam and abuse.
- Service and notification emails: to send magic link sign-in emails and account/security messages, to notify you when someone replies to your comment (on by default), and to send an optional weekly digest of your unread notifications (off by default). You can turn reply notifications and the digest on or off at any time from your notification preferences in the dashboard; every notification email also links to those settings. If you start a checkout for a paid plan and do not finish it, we may send you one email with a link to resume it; we record when that email was sent so we send it at most once every 30 days. If your account is in its free Starter feature trial, we send you one email a few days before the trial ends, saying what switches off and how to keep it; we record when that email was sent so it goes out at most once per account, ever, and not at all if you have upgraded by then. Two more one-time emails concern a site you own rather than your account: if your comment widget has been live on a site for a week and no one has commented yet, we send you one email with suggestions for getting the first comments (it offers nothing for sale); and once a site of yours has passed ten approved comments while your account is on the free plan, we send you one email saying what the Starter plan would add for that site. We record when each of those was sent on the site itself, so each goes out at most once per site, ever, and the ten-comment email is not sent at all if you already pay. Apart from that single checkout reminder, that single trial reminder, and those two one-time site emails, we do not send marketing or promotional emails: no newsletters, no product announcements, no offers.
- Knowing which pages are read: the daily per-page request totals described in §3.3 go to VectraSEO so we can see which pages of echothread.io people, search engines and AI assistants reach, and decide what to write next. They are counts, not records of any one visit.
- Knowing where a sign-up came from: when you create an account we record the campaign or referring site that first brought you to echothread.io (§3.3), so we know which channels are worth continuing. It is captured once, on your first visit, and tells us nothing about what you did on the site.
- Spam detection: when a new comment is submitted, its text is sent to Siftfy, our machine-learning classifier operated by EchoThread, which returns a spam probability score. Siftfy receives the comment text and minimal context; it does not receive your email, IP, or browser identifiers. See §6 for Siftfy's role as a sub-processor. We additionally apply local heuristics (keyword and pattern scoring) on the server.
5. Legal basis for processing (GDPR)
If you are in the European Economic Area (EEA), United Kingdom, or Switzerland, we process your personal data on the following legal bases:
- Contract performance: processing necessary to provide the Service you signed up for (e.g., account creation, comment posting).
- Legitimate interest: spam prevention, security, service improvement, the single reminder about a checkout you started but did not finish (§4), the single reminder before your Starter feature trial ends (§4), the two one-time emails about a site you own (§4), the per-page request totals described in §3.3, and the first-touch marketing attribution described in §3.3, balanced against your rights. You may object to that attribution at any time and you do not have to give a reason — see §9.
- Consent: where required by law, such as for optional data collection (e.g., guest email).
6. Third-party services and sub-processors
We use the following services to operate EchoThread:
- Amazon Web Services (AWS): database hosting (DynamoDB), email delivery (SES), and image storage (S3). Data is stored in the US East (N. Virginia) region. AWS Privacy Policy.
- DigitalOcean: application hosting and container registry. DigitalOcean Privacy Policy.
- CloudFront (AWS): content delivery for echothread.io, static assets and the embed widget. For echothread.io only, it keeps the IP-free request logs described in §3.3 for 7 days.
- VectraSEO: the search-optimisation service we use for echothread.io itself, operated by VectraSEO LLC, the company that operates EchoThread (§2). It receives only the daily per-page request totals described in §3.3 — counts, with no IP address, cookie, user-agent string or visitor identifier — and nothing about site owners, commenters or the embed widget.
- Siftfy (operated by EchoThread): machine-learning spam classifier that receives the text of each newly-submitted comment and returns a spam probability. Hosted in the same AWS region; does not receive email, IP, or browser identifiers.
- Stripe: subscription billing for paid plans. Stripe receives the data needed to process payments (name, billing address, card details handled directly by Stripe). Stripe Privacy Policy.
- Google OAuth: used for commenter authentication in the embed widget and for site-owner sign-in to the dashboard. When you sign in with Google we receive your email, name, and profile picture.
- GitHub OAuth: used for commenter authentication in the embed widget. When you sign in with GitHub, we receive your verified primary email, display name, username, and avatar. GitHub Privacy Statement.
- X (Twitter) OAuth: used for commenter authentication in the embed widget. When you sign in with X, we receive your X user ID, name, and username. X may not share an email address; when it does not, we generate a non-deliverable placeholder address so your sign-in still works. X Privacy Policy.
- Facebook (Meta) OAuth: used for commenter authentication in the embed widget. When you sign in with Facebook, we receive your Facebook user ID, name, and profile picture. Facebook may not share an email address; when it does not, we generate a non-deliverable placeholder address so your sign-in still works. Meta Privacy Policy.
- Discord OAuth: used for commenter authentication in the embed widget. When you sign in with Discord, we receive your Discord user ID, username, display name and avatar, and your email address only when Discord reports it as verified; otherwise we generate a non-deliverable placeholder address so your sign-in still works. Discord Privacy Policy.
- KLIPY: GIF search for comments. On sites where GIFs are turned on (the default; site owners can turn them off), a reader's browser sends search words to KLIPY when they open the GIF picker, and any reader viewing a comment that contains a GIF loads that GIF from KLIPY's servers. KLIPY therefore receives that reader's IP address, browser user-agent, and any search words typed. EchoThread does not send KLIPY any account, email, or comment data, and stores only the link to a chosen GIF. KLIPY Privacy Policy.
- Bluesky and Mastodon: a commenter who signs in with Bluesky or Mastodon and ticks "Also reply on Bluesky" (or Mastodon) has that comment posted, once it is published, as a public reply from their own account on that network, where it is then governed by that network's terms and privacy policy. A site owner who connects the site's own account can post a link to a page from it. We send these networks only what is posted; never an email address or IP address.
- Destinations a site owner connects: the owner of a site can have EchoThread send new comments posted on that site to places they choose: their own server (webhooks), a Slack or Discord channel, or a Telegram chat they add the EchoThread bot to. What is sent is the comment text, the commenter's display name, the page it was posted on, and a link back to EchoThread (a webhook also carries the commenter's EchoThread user ID). We never send a commenter's email address or IP address to these destinations. Once delivered, that copy is held by the site owner and the service they chose, under their terms and privacy policies rather than ours.
We do not sell, rent, or share your personal data with any other third parties.
7. International data transfers
Your data is stored and processed in the United States. If you are located outside the US, your data will be transferred to and processed in the US. We rely on the following safeguards:
- AWS participates in the EU-US Data Privacy Framework.
- Standard contractual clauses (SCCs) where applicable.
8. Data retention
- Magic link tokens: automatically deleted after 15 minutes or upon use.
- Account data: retained for as long as your account is active. You may request deletion at any time.
- Comments: retained for as long as the associated site exists, unless deleted by the commenter or site owner.
- Uploaded images: retained for as long as the associated comment exists.
- Feedback, its context and screenshots: retained until you delete your account, when they are deleted with it.
- First-touch attribution in your browser: up to 90 days, after which your browser discards it.
- Request logs for echothread.io: 7 days, then deleted automatically. The daily per-page totals made from them contain no personal data.
9. Your rights
Depending on your location, you may have some or all of the following rights:
GDPR (EEA, UK, Switzerland)
- Access: request a copy of the personal data we hold about you.
- Rectification: correct inaccurate or incomplete data.
- Erasure: request deletion of your personal data ("right to be forgotten").
- Restriction: request that we limit processing of your data.
- Portability: receive your data in a structured, machine-readable format.
- Objection: object to processing based on legitimate interest. For the attribution described in §3.3 you can exercise this yourself, and immediately, by sending Global Privacy Control from your browser; you can also write to us.
- Withdraw consent: where processing is based on consent, you may withdraw it at any time.
- You also have the right to lodge a complaint with your local data protection authority.
CCPA / CPRA (California)
- Right to know: what personal information we collect, use, and disclose.
- Right to delete: request deletion of your personal information.
- Right to opt out: we do not sell or share personal information for cross-context behavioral advertising.
- Non-discrimination: we will not discriminate against you for exercising your rights.
LGPD (Brazil)
- You have rights to confirmation, access, correction, anonymization, portability, deletion, and information about sharing with third parties.
PIPEDA (Canada)
- You have the right to access and challenge the accuracy of your personal information held by us.
To exercise any of these rights, contact us at privacy@echothread.io. We will respond within 30 days (or sooner where required by law).
10. Cookies and local storage
EchoThread does not set first-party cookies. We use your browser's local and session storage for:
- Authentication tokens (JWT) to keep you signed in. Removed when you log out.
- Marketing attribution on echothread.io:
utm_source,utm_medium,utm_campaign,utm_content,utm_term, referring host, and landing path, kept for up to 90 days and used only to attribute a later sign-up. Stays in your browser until/unless you create an account. - Pending publisher connection: when you choose to connect a publisher's sign-in to your EchoThread account, we keep a short-lived, opaque request reference (
et_sso_link_intent) in that tab's session storage so you can refresh or sign in before reviewing the request. The reference is sent to EchoThread only to check, approve, or cancel that connection. It contains no readable publisher identity assertion or account password. We remove it after approval, cancellation, or an invalid-request response; closing the tab also ends its session storage. Restoring the screen never approves a connection automatically. - Interface state that makes a screen behave sensibly for you. Examples: a plan you clicked before signing in so checkout can resume afterwards, the page you were heading to when you were asked to sign in, your chosen language, your light or dark theme, whether you turned on browser notifications, saved filter views in your moderation queue, and your recent moderation searches, and, in the comment widget, which answer you chose in a reader poll (
et_poll_votes), so the poll shows you the results instead of asking again. These are written and read only by your own browser to render the next screen. None of them is sent to us, none records which pages you visited, and clearing your browser storage removes them all with no effect beyond losing those preferences.
The authentication token is strictly necessary to provide the Service. The marketing-attribution item is not strictly necessary. It is set on echothread.io only, is never loaded on the embed widget or commenter-facing pages — so the people who read and post comments on your site never receive it — and is not used for advertising or cross-site tracking. You can remove it at any time by clearing local storage in your browser settings, or refuse it from the outset by sending Global Privacy Control (§3.3); the Service remains fully usable without it.
11. Children's privacy
The Service is not directed to children under the age of 16. We do not knowingly collect personal data from children. If you believe a child has provided us with personal data, please contact us at privacy@echothread.io and we will promptly delete it.
12. Security
We implement appropriate technical and organizational measures to protect your personal data, including:
- Passwordless authentication (magic links, OAuth, and passkeys) to eliminate password-related breaches.
- HTTPS encryption for all data in transit.
- Encrypted storage at rest via AWS managed encryption.
- Short-lived authentication tokens with automatic expiry.
No method of transmission or storage is 100% secure. If you become aware of a security vulnerability, please report it to security@echothread.io.
13. Staff access to your account
No member of EchoThread staff can open your account. We previously operated an internal read-only "support view" that let an authorised staff member load your dashboard exactly as you see it. That capability has been removed from the Service. Nobody here can sign in as you, see your screens, or act on your behalf, and there is no setting that turns it back on. If we need to see something to resolve a support request, we will ask you for it.
Staff do still have internal tools for running the Service, and it would be misleading to imply otherwise. What they show:
- Operational records. The sites registered with us, the email address of the account that owns each one, its plan, and usage counts — so we can answer billing questions, enforce our limits, and investigate abuse.
- Comment content. Comments are the Service, so staff can see comment text and moderation state where operating it requires them to — investigating a spam or abuse report, or a moderation problem you have raised with us. This is not a view of your account; it is the content the Service stores and processes for you, described in §3.2.
- Never your access tokens. Personal access tokens are stored only as a one-way hash, so nobody at EchoThread can read one back — not staff, not us.
- Purpose limits. These tools are used to operate, support, and secure the Service. They are not used for marketing, profiling, or browsing accounts out of interest.
Records of staff access to accounts made while the support view existed are kept for 400 days from the access and then deleted. If you want to know whether your account was viewed during that period and what was seen, write to privacy@echothread.io and we will tell you from that record.
14. Changes to this policy
We may update this Privacy Policy from time to time. We will post the updated policy on this page with a revised effective date, and for material changes we will provide reasonable advance notice — for example, by email to the address on your account or by a notice on the Service — before the change takes effect. Where the law requires your consent for a new or changed use of your personal data, we will obtain that consent rather than rely on your continued use.
15. Contact us
If you have any questions about this Privacy Policy or our data practices, contact us at: