Security and privacy

Your data, your credits, your liability

Three questions come up before anyone trusts an AI agent with real customers: where does my data go, what stops bots draining my credits, and what happens if the agent says something wrong. This page is maintained by the Echo AI team and describes controls available in the product today. It is not an independent audit or a certification. Security contact: support@echoai.so

Create your Echo AI for free

Where your data lives and how it is used

Bots, spam and your credit balance

What your Echo is allowed to say

Account and access security

Compliance status

Frequently asked questions

Do you train AI models on my conversations?

No. Your knowledge and conversations are used to answer your visitors and to produce your own analytics. They are not used to train external models.

What happens to my data if I close my account?

It is deleted. Closing the account removes your Echos, conversations, documents, contacts and integration tokens. There is no dormant copy waiting to be reactivated.

Can a bot drain my credits?

That is what the rate limits, spam thresholds, IP bans and link filters are for. Automated floods are rejected before the model runs, so they do not consume credits. Credit history shows every action, and low balance alerts warn you early.

What if my Echo says something wrong or legally risky?

Answers are grounded in the material you provide, and a pre-filter escalates refund, legal, medical and complaint topics to a human instead of answering. You can pause the Echo instantly, review the full transcript and fix the knowledge behind it. The agent speaks for your business, so the guardrails are yours to configure.

Are you GDPR compliant?

We follow GDPR aligned practices, including cookie consent, data minimisation options, PII anonymisation and self serve export and deletion. Compliance also depends on how you use the platform. For a DPA or a security questionnaire, contact support@echoai.so.

Do you have SOC 2 or ISO 27001?

Not yet. We are building towards SOC 2 Type II readiness and ISO 27001 aligned practices, and we will publish the status here when that changes.