Privacy Policy — Echo

Last updated: 26 August 2026

This Privacy Policy describes how Agylos collects, uses and protects your personal data when you use the Echo mobile application (hereinafter "Echo" or the "app").

Echo is distributed in the European Union and in Canada.

It serves as the information notice required by Articles 13 and 14 of the General Data Protection Regulation (Regulation (EU) 2016/679, "EU GDPR"). For users resident in Canada, additional rights under the Personal Information Protection and Electronic Documents Act (PIPEDA) and, for Québec residents, under Loi 25 (An Act to modernize legislative provisions as regards the protection of personal information), are described in §7.1.

1. Data controller

The controller of your personal data is:

Agylos, a French société par actions simplifiée (SAS) with a share capital of EUR 5,000, registered with the Nanterre Trade and Companies Register under number 815 320 528, whose registered office is at Bâtiment E, 15 Rue des Bigots, 92190 Meudon, France, represented by Pierre Navarre, in his capacity as President.

For any question concerning your personal data or this Privacy Policy, you may contact Agylos by email at privacy.echo@agylos.eu.

Agylos has not appointed a Data Protection Officer within the meaning of Article 37 GDPR. None of the three criteria of Article 37(1) is met at the time this Policy is published: (a) Agylos is not a public authority or body; (b) its core activities do not require regular and systematic monitoring of data subjects on a large scale; (c) its core-activity processing of special categories of data (Art. 9 — main well-being concern T-14) does not reach the "large scale" threshold within the meaning of EDPB Guidelines WP243, given the volume expected at PMV (a few hundred to a few thousand active users, EU + Canada scope). Agylos may appoint a DPO on a voluntary basis as the volume or scope of the service evolves.

2. Personal data we collect

Echo only collects data strictly necessary to operate the service. The categories below correspond to entries in the internal Record of Processing Activities kept by Agylos under Article 30 GDPR.

2.1. Identification and authentication data

2.2. Profile data

2.3. Content you enter in the app

2.4. Technical and measurement data

2.5. Correspondence data

Echo never collects: your location, your contacts, your photos, your HealthKit data, your address book, or your device's advertising identifier (IDFA).

3. Purposes and lawful bases

Each processing activity is grounded in a specific lawful basis under Article 6 GDPR.

PurposeData categoriesLawful basis
Allow you to create an account and access the service (Sign in with Apple, identity management) 2.1 Performance of the service contract you enter into with Agylos by installing Echo (Art. 6(1)(b) GDPR)
Verify that the recovery email address you enter in your profile belongs to you (sending of a one-time verification link) 2.1 (recovery email address) Explicit consent (Art. 6(1)(a) GDPR) — collected when you enter the address in the Profile section. You may remove the address at any time from that section, which counts as withdrawing your consent (Art. 7(3) GDPR)
Personalise the service and verify the minimum age requirement 2.2 Performance of the contract (Art. 6(1)(b) GDPR)
Deliver the core longitudinal tracking feature and the weekly appointment 2.3 Performance of the contract (Art. 6(1)(b) GDPR)
Personalise your coaching experience from the main well-being concern you share with us (message as written + categorisation across seven themes) — the raw message powers a personalised welcome from the coach at sign-up and helps us improve our services through aggregated analytics that carry no individual identifier; the categorisation shapes the conversation and the weekly appointment 2.2 (primaryConcern, primaryConcernRawText and consents.primaryConcernAcceptedAt) Explicit consent (Art. 9(2)(a) GDPR) — this relates to your health, and consent is collected via a dedicated checkbox, separate from the acceptance of our Terms and Privacy Policy. The checkbox indivisibly covers both keeping your message as you wrote it and its general categorisation. You may withdraw this consent at any time from the Privacy section of your profile (Art. 7(3) GDPR) — withdrawal then erases, in the same atomic operation, your message, its categorisation and the record of your consent; to share a new concern later, you will be asked to give your consent again (see §4.8)
Measure product usage (funnels, completion, retention) via Firebase Analytics 2.4 (Analytics events) Consent (Art. 6(1)(a) GDPR), complemented by Article 82 of the French loi Informatique et Libertés (ePrivacy transposition). Consent is requested during sign-up, as an explicit choice between accepting and declining — no answer is pre-selected and collection only starts once you have accepted. You may change your choice at any time, either way, from the "Usage analytics" toggle (Profile → Advanced settings → Privacy and data)
Detect and fix application crashes via Firebase Crashlytics 2.4 (crash reports) Legitimate interest of Agylos in maintaining service stability (Art. 6(1)(f) GDPR)
Attribute installs to their marketing source (Firebase App Attribution, SKAdNetwork level 1) 2.4 (attribution) Legitimate interest of Agylos in measuring campaign effectiveness (Art. 6(1)(f) GDPR)
Calibrate the statistical pre-processing algorithms of the weekly appointment (pseudonymised BigQuery instrumentation) 2.3 (pseudonymised) Legitimate interest of Agylos in improving coach relevance (Art. 6(1)(f) GDPR). Full description in §4.5
Answer your support requests and your requests to exercise your data subject rights 2.5 Performance of the contract (Art. 6(1)(b) GDPR) and legal obligation of Agylos to respond to data subject requests within statutory deadlines (Art. 6(1)(c) GDPR)
Maintain the audit report of account deletion requests See §4.4 Legal obligation of Agylos to demonstrate GDPR compliance (Art. 5(2) and Art. 30 GDPR; basis Art. 6(1)(c))

Data 2.1 (identifiers, session), 2.2 (onboarding profile) and 2.3 (indicators and appointment) are necessary to perform the service contract — without them Echo cannot function. Data 2.4 (analytics, crash, attribution, BigQuery) rely either on consent (Firebase Analytics, opt-in) or on legitimate interest, which you may object to directly in-app (see §7). The main well-being concern (primaryConcern + primaryConcernRawText, T-14) is optional — its absence does not prevent you from using Echo but degrades the coaching personalisation the coach can offer you.

Echo does not use your data for any advertising purpose, does not carry out individual profiling, and does not take any automated decision that produces legal effects concerning you or similarly significantly affects you within the meaning of Article 22 GDPR. The AI coach assists you but takes no medical, financial or administrative decision on your behalf.

4. Retention periods

Agylos only retains your data for as long as is strictly necessary for the purposes described above.

4.1. Account and profile data

Your account, profile and tracking indicator data are retained for the entire lifetime of your account. They are erased immediately when you delete your account from the app ("Delete my account" button in the Privacy section of your profile).

To honour the storage-limitation principle (Art. 5(1)(e) GDPR), Agylos also enforces an inactive-account purge policy. After 24 months without any sign-in, we send a reminder email to the address associated with your account, inviting you to sign back in. If you do not sign back in within the following 12 months (a total of 36 months of inactivity), your account is automatically deleted, as if you had triggered the deletion yourself. The erasure cascade described in §4.2 to §4.7 then applies identically.

4.2. Weekly appointment content

Chat messages and appointment summaries are retained for the entire lifetime of your account and erased upon its deletion. Anthropic's processing cache is limited to a short technical caching window (minutes at most) and Anthropic does not use your messages to train its models ("zero-training" option).

4.3. Product measurement (Firebase Analytics)

Firebase Analytics data is retained for 14 months and then automatically purged by Google. When you delete your account, the Agylos support team additionally submits a full deletion request to Google Firebase Analytics. Deletion on the Firebase Analytics side is executed manually by the support team within 30 days at most after your account deletion (internal SLA documented in Annex D of the Record of Processing Activities).

4.4. Account deletion audit report

The internal audit report Agylos produces when you delete your account contains only your technical Firebase identifier (uid) and the technical status of the deletion steps (the identity itself has already been erased). It is retained for a rolling 3-year period for the purpose of demonstrating compliance (Art. 30 GDPR).

4.5. Pseudonymised weekly appointment instrumentation

The statistical calibration data for the weekly appointment (numerical indicator values, pre-processing outputs) is stored in the European Union (Belgium, europe-west1) for a maximum of 90 days in detailed form, and then retained in aggregated form without any individual identifier. Your user identifier is replaced by an irreversible hash (SHA-256) before any write operation. No free-text content of your messages is stored in this instrumentation.

4.6. Crashlytics

Crash reports are retained for 90 days by default in Firebase Crashlytics.

4.7. Support correspondence and data subject requests

Emails exchanged with support and evidence of the handling of data subject requests are retained for 3 years after case closure, for traceability and to demonstrate compliance.

4.8. Main well-being concern (primaryConcern)

Your main well-being concern — your message as you wrote it (up to 1,000 characters) together with the categorisation of that message across the seven themes stress, anxiety, sleep, depression, burnout, relationships, other — is retained for the entire lifetime of your account, subject to the same inactive-account purge policy as described in §4.1. It can also be erased independently, without deleting your account, if you withdraw your Article 7(3) GDPR consent at any time from the Privacy section of your profile (see §7 and §8). Withdrawal then erases, in the same atomic operation, three items at once: your message as written, its categorisation, and the record of your consent to processing this health-related data. If you later wish to share a new concern with Echo, you will be asked to give your consent again (re-tick the "Health data" checkbox) and to rewrite your message: we keep nothing that would exempt you from this fresh consent. Erasure is immediate on the Echo side; the coach stops using this signal at your next session. Your other consents (Terms of Service and Privacy Policy) are not affected by this action.

4.9. Recovery email address and verification email sending

When you enter a recovery email address in your profile, Agylos sends you a one-time verification link through its partner Sinch (Mailgun EU), based in Frankfurt, Germany. Data is transferred to and stored within the European Union — no transfer outside the EU. The link expires after 24 hours; past this window it is no longer usable and a new link must be requested from the Profile section.

On the Agylos side, the verification link is stored as an irreversible hash (SHA-256); the clear value only transits in the outgoing email. The link is erased as soon as it is consumed (first click), when you remove your recovery email address from the Profile section, or when you delete your account. On the Mailgun side, technical sending logs are retained for a maximum of 3 days (Mailgun EU default policy) and do not contain any application-level content beyond your address and delivery metadata.

Lawful basis: explicit consent (Art. 6(1)(a) GDPR), see §3. Removing your recovery email address from the Profile section counts as withdrawing your consent (Art. 7(3) GDPR) — the associated record is immediately erased on the Agylos side.

5. Recipients and processors

Agylos does not sell, rent or transfer your data to any third party.

Your data is accessible to:

ProcessorRoleContractual framework
Google LLC / Google Ireland Ltd (Firebase Authentication, Firestore, Firebase Analytics, Firebase Crashlytics, Firebase App Attribution, Firebase Hosting, BigQuery, Cloud Logging, Secret Manager) Hosting, authentication, product measurement, application stability Google Cloud DPA and the Standard Contractual Clauses adopted by the European Commission — cloud.google.com/terms/data-processing-addendum
Anthropic PBC (Claude, the LLM powering the coach) Assisted generation of coach messages during the weekly appointment; personalisation of coaching from the main well-being concern you share, where you have consented to it — including the automatic categorisation of your sign-up message across the seven themes stress / anxiety / sleep / depression / burnout / relationships / other (Claude Haiku 4.5) and the generation of the personalised welcome bubble right after your sign-up Anthropic DPA and Standard Contractual Clauses — anthropic.com/legal/dpa. "Zero-training" option enabled across all uses. Pseudonymised context (no first name, no date of birth transmitted to Claude).
OVH SAS (Roubaix, France) Hosting of the messaging services privacy.echo@agylos.eu and support.echo@agylos.eu Article 28 GDPR data processing agreement — processing within the European Union, no transfer outside the EU
Sinch (Mailgun EU) (Frankfurt, Germany) Sending of the transactional email carrying the verification link for your recovery email address (see §4.9) Sinch/Mailgun DPA and Standard Contractual Clauses — mailgun.com/legal/dpa-changelog. Data transferred to and stored within the European Union (Frankfurt), no transfer outside the EU. Technical sending logs retained for 3 days on the Mailgun side.

Independent controllers your data is shared with for their own purposes. Certain technical operations involve Apple Inc., which acts as an independent data controller — Apple sets its own purposes (Apple ID identification, SKAdNetwork audience measurement), applies its own end-user terms, does not process these data on Agylos's instructions and does not sign an Art. 26 joint-controller arrangement. The processing activities concerned are:

Agylos has no ability to instruct Apple on these processing activities. For the exercise of your rights vis-à-vis Apple, refer to Apple's Privacy Policy: apple.com/legal/privacy.

6. International transfers

Data stored in Firestore and BigQuery is held at rest within the European Union, in the europe-west1 (Belgium) region.

However, certain processing activities involve technical infrastructure located in the United States:

These transfers are governed by the Standard Contractual Clauses adopted by the European Commission (Implementing Decision 2021/914), which are incorporated into the Google Cloud and Anthropic DPAs referenced in §5. For Canadian users, the same Google Cloud Standard Contractual Clauses also frame the transfer of personal data to Google infrastructure located in the United States (see §7.1).

Agylos does not carry out any transfer other than those described above.

7. Your rights

Under Chapter III GDPR, you have the following rights over your personal data:

7.1. Additional rights for Canadian users

If you are resident in Canada, the processing of your personal data by Agylos in connection with Echo is additionally covered by Canadian privacy legislation.

PIPEDA (federal). Under the Personal Information Protection and Electronic Documents Act, you have, in particular:

You may lodge a complaint with the Office of the Privacy Commissioner of Canadapriv.gc.ca.

Loi 25 (Québec). If you are resident in Québec, you also benefit from the additional protections of the Act to modernize legislative provisions as regards the protection of personal information (Loi 25), which strengthens transparency, information and consent obligations, and provides for a right to de-indexation and a right to data portability.

You may lodge a complaint with the Commission d'accès à l'information du Québec (CAI)cai.gouv.qc.ca.

A French-language version of this Privacy Policy is available at echo.agylos.eu/privacy-policy for Québec French-speaking users, and now includes a §7.1 mirroring the present section (PIPEDA + Loi 25) so Québec francophone users can access the same regulatory information in French.

7.2. Rights of European Union users

You may lodge a complaint with the supervisory authority of your Member State of residence, place of work or place of the alleged infringement (Art. 77 GDPR), or with the French Commission Nationale de l'Informatique et des Libertés (CNIL), 3 Place de Fontenoy, TSA 80715, 75334 Paris Cedex 07, France — cnil.fr.

8. How to exercise your rights

Most of the rights above can be exercised directly in the app:

For any request not covered by these in-app controls (for example, a full access request or exercising the right to restriction), write to privacy.echo@agylos.eu and mention the email address associated with your Echo account.

Agylos will respond to your request within one month of receipt (Art. 12(3) GDPR). This period may be extended by two further months for particularly complex requests; where this applies, Agylos will inform you within the first month.

Agylos may ask you for reasonable proof of identity (for example, confirmation of the email address associated with your account) before acting on your request, to protect you against fraudulent requests.

9. Cookies, trackers and equivalent technologies

Echo is an iOS mobile application; it does not use HTTP cookies.

It embeds the following technologies:

You may object at any time to the Firebase Analytics processing in the Privacy section of your profile (see §7).

10. Future evolutions

Echo may in the future integrate data from external connectors — weather information, geolocation, health data from HealthKit (iOS) or Health Connect (Android) — to enrich its coaching capabilities.

None of these categories of data are collected today. No activation will take place without your prior explicit consent, collected directly in the app at the moment the relevant feature is offered. This Privacy Policy will be updated ahead of any such activation, and you will be notified through the channels described in §11.

11. Changes to this Privacy Policy

Agylos may amend this Privacy Policy, for example to reflect service changes, a change of processor, or a regulatory update.

The "Last updated" date at the top of this document is always accurate. In the event of a material change, Agylos will notify you via an in-app notification and, where appropriate, by email to the address associated with your account.

The current version is published at echo.agylos.eu/privacy-policy-en.