Legal

Privacy Policy

Effective date: August 24, 2026

1. What this policy covers

EchoraIQ is operated by Aeronis Lab Technologies - FZCO, a free zone company registered in the United Arab Emirates at Building A5, Dubai Digital Park, Dubai Silicon Oasis, Dubai, United Arab Emirates. That company is the data controller for the information described here, and is what “we” and “us” mean throughout this policy.

This Privacy Policy explains how we collect, use and protect information when you use the EchoraIQ platform — our social listening, engagement and publishing workspace — and the websites that link to it.

2. Information we collect

Account information: your name, email address, workspace name and role, provided when a workspace is created or when you are invited to one.

Connected-channel data: when you connect a social account (for example Facebook, Instagram, X, YouTube, Reddit or Google Business), we receive OAuth tokens and the content those platforms authorize — such as posts, comments, messages and reviews addressed to your accounts. Tokens are envelope-encrypted at rest and used only to provide the service you configured.

Public social content: mentions and posts matched by monitors you create, retrieved from platform APIs under each platform’s terms.

Usage and security data: sign-in events, approvals and administrative actions are recorded in a tamper-evident audit log to protect your workspace.

2a. Signing in with Google, and Google account data

If you choose “Continue with Google”, we ask Google only for your basic identity — the openid, email and profile scopes. That gives us your email address, your name and your profile picture, and nothing else. We use them for exactly one purpose: to identify you and sign you in to your workspace. We never receive or request your Google password, and we cannot read your Gmail, Drive, Calendar or Contacts.

Connecting a Google Business Profile is a separate, optional action that you start yourself from inside the app. It uses a different authorization, and we request it only to list the locations you manage, read the reviews left on them, and post the replies you write. Connecting YouTube is likewise separate and optional; section 2b below sets out in full what we access there and why.

EchoraIQ’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not sell Google user data, we do not transfer it except to provide or improve the features you asked for, and we do not use it for advertising or to train generalized AI models. You can disconnect any Google account at any time from the Connections page in your workspace, which revokes our access.

2b. YouTube API Services

EchoraIQ uses YouTube API Services. Connecting a YouTube channel is optional and you start it yourself from the Connections page inside your workspace. By connecting a channel — or by using any EchoraIQ feature that reads YouTube content — you also agree to the YouTube Terms of Service. Google’s own handling of your information is governed by the Google Privacy Policy.

What we access. With your authorization we request exactly two YouTube scopes: youtube.readonly, to read your channel and the videos and comments on it; and youtube.force-ssl, to publish the comment replies you write and to moderate comments on your own videos. Separately, monitors you create can search publicly available YouTube videos and their public top-level comments for the terms you track, through the YouTube Data API, using either that same authorization or a YouTube Data API key your workspace supplies. We never receive or request your Google password, and we cannot read your Gmail, Drive, Calendar or Contacts.

How we use it. YouTube data is used only to deliver the features you configured: showing your channel’s videos and comments inside your workspace, surfacing matching public videos and comments as mentions, scoring their sentiment, and sending the replies you write back to YouTube. We do not sell YouTube data, we do not use it for advertising, and we do not use it to train generalized AI models.

Where it is stored, and who can see it. OAuth tokens are envelope-encrypted at rest; channel, video, comment and mention records are held in our own infrastructure and are visible only to the members of your workspace whose role allows it. We disclose YouTube data to no one else, with three exceptions: the service providers that host our infrastructure under confidentiality obligations; our AI model provider (OpenAI), which processes the text of a mention or message when you use an AI feature on it or when automatic sentiment scoring applies, and which does not use that text to train its models; and any authority where the law requires it. Workspaces whose policy forbids external processing, including government workspaces, are excluded from all external AI processing automatically.

Deleting YouTube data, and revoking our access. You can stop and undo our access yourself, in either of two places, without contacting us. In your workspace, the Connections page offers Disconnect — which deletes the stored token and halts all YouTube access immediately — and Delete, which additionally removes the connection together with the channel and account records stored under it. At Google, the Google security settings page lets you withdraw EchoraIQ’s authorization for your Google account at any time. YouTube content that your monitors collected is stored as mentions while your workspace is active; to have that content, or your whole workspace, deleted, email us at contact@echoraiq.com and we will delete it and confirm when it is done.

3. How we use information

To operate the platform: display mentions, deliver your replies and posts, sync reviews, and meter usage against the limits you set.

To secure the platform: enforce role-based access, detect misuse and maintain the audit trail your administrators rely on.

We do not sell personal information, and we do not use your content to train third-party AI models. AI features are powered by a third-party model provider (OpenAI) under our own account: reply drafting, translation and message analysis process the specific text you choose, while sentiment scoring may automatically process the text of collected mentions and messages to classify them. Workspaces whose policy forbids external processing (including government workspaces) are excluded from all external AI processing automatically.

4. Sharing, processors, and where data is processed

We share data only with: (a) the social platforms you connect, to carry out actions you request; (b) the service providers listed below, under confidentiality obligations and only to run the service; and (c) authorities where the law requires it. We do not sell personal information, and we do not share it for advertising. Workspace administrators control what their members can see and do.

The providers we rely on are: our cloud hosting provider, which runs the application and its databases; Zoho ZeptoMail, which delivers transactional email such as sign-in and password-reset messages; Razorpay, which processes payments — we never see or store your card details; OpenAI, which powers the optional AI features (reply suggestions, translation, sentiment); and Data365, which collects public social posts for the optional listening add-on that works without connecting an account. Data365 receives only the keywords a workspace chooses to monitor, and returns publicly posted content; it is used only by workspaces that have bought listening credits. Each provider receives only what that function needs.

We are established in the United Arab Emirates and operate from Dubai. Because the platforms you connect, the providers above, and your own team may be located elsewhere, personal information is transferred internationally in the ordinary course of running the service. Where that happens we rely on contractual protections with each provider and send only the data the function requires.

Two controls change this for government workspaces, and they are enforced in the product rather than promised in policy: third-party egress is switched off entirely — no tenant content reaches an external AI model, and the third-party listening provider above is never used for a government workspace, whose monitors run only against the accounts it has connected itself; and the workspace can be pinned to a data region. Commercial workspaces may also request region pinning.

4b. Cookies and the support chat

We use cookies only to run the service. There is no advertising cookie, no analytics cookie and no third-party tracker on this site, which is why you are not asked to accept anything: every cookie below is strictly necessary for a feature you asked for, and none of them profiles you.

Signing in sets two cookies (sl_access, sl_refresh) that keep you signed in. They are HttpOnly, so no script can read them, and host-only, so they are never sent to any other subdomain. Signing in with Google briefly sets two more (eq_gsi_nonce, eq_gsi_pending) which exist only for the length of that redirect. The partner portal uses its own separate cookie (eq_partner_access).

One cookie is not about signing in. If you arrive through a partner’s referral link, we store that partner’s code (eq_ref) for 90 days so the partner is credited if you later subscribe. It holds a referral code and nothing else — no identifier for you, and nothing that follows you to another site. Deleting it in your browser stops the attribution, and refusing it costs you nothing.

The support chat on our public pages is provided by a third party and loads its own script and storage when it appears. It runs only on the marketing pages: it is never loaded inside a signed-in workspace, so it cannot see your content, your messages or anything you type into the product.

5. Retention and deletion

Content and account data are retained while your workspace is active. Audit records may be retained for up to seven years where your organization’s policy requires it. You may disconnect a channel at any time, which revokes our access; deleting a connection removes its stored tokens together with the accounts and conversations stored under it.

Deleting a whole account or workspace is done on request rather than from a button in the product. Email contact@echoraiq.com from the address on the account. We will confirm the request, delete the workspace and everything held under it — users, connections, stored tokens, media, and collected mentions — within 30 days, and confirm in writing when it is done. Audit records and records we must keep for tax or accounting purposes are the exception, and are retained for the periods described above. Backups are overwritten on their normal cycle, so a copy may persist in an offline backup for up to 35 days after deletion.

Data obtained from Google and YouTube has its own deletion and revocation route, set out in section 2b above — including the Google security settings page, where you can withdraw our access to your Google account directly.

6. Security

We protect data with encryption in transit and at rest, envelope-encrypted credentials, multi-factor authentication (including passkeys), deny-by-default role-based access control and a hash-chained audit log. No system is perfectly secure, but security is the core design constraint of this platform.

7. Your rights

As a company established in the United Arab Emirates, we handle personal information in line with UAE Federal Decree-Law No. 45 of 2021 on the Protection of Personal Data. You may ask us to access, correct, export or delete your personal information, to restrict or object to a particular use, or to withdraw a consent you gave. Email contact@echoraiq.com and we will respond within 30 days.

If you are in the European Economic Area or the United Kingdom, the GDPR gives you the same rights and we honour them on the same timeline, including the right to complain to your local supervisory authority. Nothing in this policy limits a right you hold under the mandatory law of the country you live in.

If you interact with an EchoraIQ customer’s social account, that customer is the controller of your message content and we process it on their behalf — send your request to them, and we will support them in answering it.

8. Changes & contact

We will post any changes to this policy on this page with an updated effective date. Questions or requests, including access, correction and deletion: contact@echoraiq.com.

Data controller: Aeronis Lab Technologies - FZCO, Building A5, Dubai Digital Park, Dubai Silicon Oasis, Dubai, United Arab Emirates. Company website: aeronislab.com.