1. Introduction
Paper Star, Corp. ("we," "our," or "us") provides the Echo application and services. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our application and services.
2. Local and Cloud Data
Echo is an open-source application that requires an account. The desktop app stores notes, transcripts, summaries, and meeting data in Echo's local database and associated application files on your device. On mobile, Echo uploads completed recordings to its service and sends them to Soniox or ElevenLabs for transcription. Echo then sends the resulting transcript text to OpenAI to create your note and summary. File-based recording uploads are not retained after transcription. Supported notes, transcripts, summaries, meeting metadata, and non-recording attachments also sync automatically to your Echo account, subject to your plan's history limits. Raw meeting recordings are not uploaded by Cloud Sync. Separately, if the "Share recordings and notes to improve Echo" preference is enabled for your account, Echo retains a server-side copy of the audio from live hosted transcription sessions for product improvement, as described in Section 3.4. Hosted transcription and AI features require an internet connection. If you no longer wish to maintain your account, you can initiate account deletion in Echo's Settings or contact us atsupport@paperstar.cc.
3. Information We Collect
3.1 Information You Provide
We collect information that you directly provide to us, including:
- Account Information: Name, email address, password, and profile information
- User Content: Notes, transcripts, summaries, meeting metadata, non-recording attachments, and other content included in Cloud Sync or that you choose to share
- Payment Information: Billing details and payment card information, processed securely through third-party payment processors
- Communications: Information you provide when you join the waitlist, complete a waitlist survey, or contact us for support or feedback
In-app feedback may include the message and images you choose to submit, along with your account email, an internal account identifier, the Echo version, and the in-app entry point you used. We store this feedback in our cloud database and copy it to a private support channel in Slack so our team can review it.
3.2 Information Collected Automatically
When you use the Service, we may automatically collect:
- Usage Data: Anonymous information about how you interact with the Service, including product interaction events (such as onboarding, downloads, note creation, transcription, summary generation, exports, and settings interactions)
- Device Information: Device type, operating system, browser type, and IP address
- Log Data: Access times, pages viewed, system activity, and technical diagnostics (latency, status codes, error events)
- Website Analytics Data: On Echo-owned websites, behavioral metrics, click and scroll activity, referrers, approximate location derived from IP address, browser/device information, and similar interaction metadata
- Service Telemetry Metadata: Pseudonymous identifiers, app/browser version metadata, and cloud feature usage metadata (speech-to-text duration, AI token counts, AI latency, provider/model metadata) used for operations, billing, product improvement, and abuse prevention
Analytics and telemetry events are designed to avoid raw meeting audio, transcript text, note content, and summary text.
3.3 Google Calendar and Microsoft Outlook Calendar Accounts
If you connect Google Calendar or Microsoft Outlook Calendar, we use the Google Calendar API or Microsoft Graph, respectively, to collect and process the data needed to display your calendars and upcoming events in Echo and let you create personal notes and memos associated with those events. This may include:
- Calendar Information: Calendar IDs, names, colors, access or ownership metadata, and source or account identifiers
- Event Information: Event IDs, titles, descriptions, locations, meeting links, start and end times, time zones, recurrence metadata, organizer details, and attendee details such as names, email addresses, and RSVP status
- Connection Information: Provider connection IDs, connection status, and the Google or Microsoft account identity associated with the connection
We use connected calendar data to display calendars and upcoming events and to support the personal notes and memos you create for those events. The desktop app requests this data directly from Google or Microsoft; calendar API responses do not pass through Echo's servers or an integration proxy. When you use hosted transcription for an event-linked session, Echo may send the event title, description, location, and attendee names to the selected speech-to-text provider as keyword hints that improve recognition. When you use hosted AI from an event-linked note, Echo may include the event name in the note context sent to the model. If you ask a hosted AI model about your schedule, Echo may also send matching event titles, times, locations, meeting links, and descriptions so it can answer. We do not use connected calendar data for advertising, marketing personalization, sale to data brokers, or training generalized AI models. The use of information received from Google Workspace APIs adheres to the Google Workspace API User Data and Developer Policy, including the Limited Use requirements.
3.4 Product Improvement Recordings and Notes
Echo accounts have a "Share recordings and notes to improve Echo" preference. It is enabled by default, applies across your signed-in devices, and can be turned off at any time in the desktop app's Settings. While it is enabled, we collect:
- Meeting Audio from Hosted Transcription: When you use hosted (cloud) transcription for a live session, Echo retains a server-side copy of the same audio it already streams to the speech-to-text provider — your microphone and, when captured, remote or system audio — stored as one compressed recording per session
- Associated Notes: Notes from those shared sessions, which already sync to your Echo account, may also be used for product improvement
- Recording Metadata: Technical details about each shared recording, such as duration, audio channel count, sample rate, file size, the transcription provider used, and an internal session identifier
Sessions transcribed with on-device models never leave your device and are never collected this way, and dictation and file-based transcription uploads are not retained. Sharing is forward-only: it applies only to sessions that start while the preference is on. Nothing recorded before you enable it can be collected, and turning it off stops collection from your next session onward but does not automatically delete recordings already shared. The internal session identifier is used only to associate a shared recording with its session and is not sent to speech-to-text providers.
Shared recordings are stored in access-restricted cloud storage that has no in-app or API access — not even for the account that shared them — and can only be read with Echo's backend service credentials. They are deleted when your account is deleted, and you can request earlier deletion as described in Section 7.3.
4. How We Use Your Information
We use your information to:
- Provide, maintain, and improve the Service
- Process transactions and manage your account
- Send technical notices, updates, and support messages
- Send marketing communications (newsletters, product announcements, updates) — you may opt out at any time
- Display calendars and upcoming events and support event-related notes and memos when you connect Google Calendar or Microsoft Outlook Calendar
- Improve transcription quality and other product features using recordings and notes shared under the "Share recordings and notes to improve Echo" preference (Section 3.4)
- Respond to your comments, questions, and requests
- Protect against fraud and other illegal activities
- Comply with legal obligations
5. Data Storage and Security
We implement appropriate technical and organizational security measures to protect your information against unauthorized access, alteration, disclosure, or destruction. We use HTTPS/TLS to protect data transmitted over external networks. The operating system controls at-rest protection for data stored locally on your device, including any device-level encryption you enable.
For connected calendars, calendar and event data is stored in Echo's local application database on your device. Google and Microsoft refresh tokens are stored in your operating system's credential vault and as an encrypted, account-scoped recovery copy in Echo's backend, so your calendar connection can be restored on another signed-in device. Echo retains credential-free disconnect records to prevent an older device from restoring a disconnected account. Calendar-derived keyword hints are sent only when you use hosted transcription for an event-linked session. Hosted AI may receive an event name from an event-linked note or matching event details when you ask about your schedule. Event context attached to a note may also be included in automatic Cloud Sync or content you choose to share.
No method of transmission over the Internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your information, we cannot guarantee its absolute security.
6. Data Sharing and Disclosure
6.1 We Do Not Sell Your Data
We do not sell, trade, or rent your personal information to third parties, including connected calendar data.
6.2 Service Providers
We may share your information with third-party service providers who perform services on our behalf, such as:
- Cloud hosting and infrastructure providers (e.g., Vercel, Fly.io, Cloudflare, Supabase) for hosting our application and storing data securely
- Payment processors (e.g., Stripe) for processing payments securely
- Analytics services (e.g., PostHog) for understanding how users interact with our Service
- Speech-to-text providers (e.g., OpenAI, ElevenLabs, Soniox) for cloud-based transcription when you enable this feature, including calendar-derived keyword hints for event-linked sessions
- AI model providers (currently OpenAI) for hosted AI features when you use them, including mobile transcript text used to create notes and summaries, event names attached to note context, and matching calendar event details when you ask a hosted model about your schedule
- Error monitoring services (e.g., PostHog and Sentry, with Sentry limited to native desktop crash reports) for identifying and fixing issues
- Email services (e.g., Resend) for sending transactional and marketing communications
- Team communication services (e.g., Slack) for reviewing waitlist submissions and responding to feedback you submit
6.3 Connected Calendar Data Sharing
When you connect Google Calendar or Microsoft Outlook Calendar, we may share connected calendar data only:
- With service providers directly involved in authenticating the connection, syncing calendars and events, and delivering the calendar features you enable
- Through encrypted Cloud Sync or content you choose to share when event context has been associated with a note
- For security purposes, such as investigating abuse, preventing fraud, or fixing integration failures
- To comply with applicable law, regulation, legal process, or enforceable governmental request
- As part of a merger, acquisition, or asset sale, only after obtaining your explicit prior consent
We do not sell connected calendar data or transfer it to third parties for advertising, marketing, or data broker purposes.
We do not permit employees, contractors, or other people to read connected calendar data unless you give explicit consent for support involving specific data, access is necessary to investigate a security issue or abuse, or access is required by applicable law.
6.4 Legal Requirements
We may disclose your information if required by law or in response to valid requests by public authorities (court orders or government agencies).
7. Your Rights and Choices
7.1 Access and Portability
Your notes are stored locally on your device and supported content also syncs to your Echo account. You can access notes in Echo and use Echo's export tools to create portable copies.
7.2 Correction and Deletion
You may initiate account deletion from Echo's Settings or request it by contacting us at support@paperstar.cc. Account deletion does not itself remove Echo's local application files from your device, but an account is required to use Echo.
7.3 Data Retention
If you connect Google Calendar or Microsoft Outlook Calendar, calendar and event data is retained locally on your device. Disconnecting deletes the provider credential from the operating system credential vault, stops future access, and removes the data from active calendar views after Echo refreshes, but underlying local records and event context already associated with notes may remain until you remove local Echo app data. You can also revoke Echo from your Google or Microsoft account settings. We delete cloud-stored data controlled by Paper Star, Corp. within 30 days of an applicable deletion request, except where required to retain it for legal purposes. In-app feedback and its image attachments remain associated with your account and are included in account deletion, including the copies mirrored to Slack.
7.4 Analytics and Telemetry Controls
- Desktop app setting: You can disable desktop usage analytics in Settings (
Share usage data). - Global Privacy Control: We honor Global Privacy Control (GPC) for non-essential website tracking.
7.5 Connected Account Controls
You can choose which calendars Echo displays or disconnect an account from the Calendar sidebar. Disconnecting stops future access and syncs; it does not delete personal notes or memos you created. You can revoke Echo's access from your calendar provider. Permanently removing local calendar data currently requires removing all local Echo app data from that device.
7.6 Product Improvement Sharing Controls
You can turn "Share recordings and notes to improve Echo" off at any time in the desktop app's Settings. Turning it off stops collection from your next hosted transcription session onward. Recordings already shared are not automatically deleted when you turn the preference off, but you can request their deletion by contacting us at support@paperstar.cc, and they are deleted when your account is deleted.
8. International Data Transfers
Your information may be transferred to and maintained on computers located outside of your jurisdiction where data protection laws may differ. By using the Service, you consent to such transfers.
9. Children's Privacy
Our Service is not intended for children under 13. We do not knowingly collect personal information from children under 13.
10. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the date above.
11. Contact Us
If you have any questions about this Privacy Policy, please contact us at:
Paper Star, Corp.
Email: support@paperstar.cc