Get Ekko

Privacy

What we know. What we can't know.

Ekko is designed to minimize the information available to us. This policy explains what stays on your device, what our services receive, and why. Last updated July 17, 2026.

Ekko processes message content and cryptographic keys on your device. It does not send plaintext messages or unencrypted private keys to Ekko, Supabase, or any other account provider. Encrypted messages travel through the messaging service you chose, which continues to receive the ordinary account, recipient, timing, and delivery metadata needed to carry them.

Supported messaging sites: the browser extension runs on Instagram, WhatsApp Web, Telegram Web, and Messenger. It reads only the page content needed to identify the open direct conversation, encrypt a draft you choose to send, replace that draft with ciphertext, and recognize and decrypt Ekko messages. This processing happens locally. Ekko does not use it to record browsing history, log keystrokes, build advertising profiles, or analyze your conversations. Because Ekko works as a layer over another service, that service can still observe its own page and any text present before Ekko replaces it.

Storage on your device: Ekko uses browser or app storage for your encrypted identity vault, contacts' public keys and handles, conversation bindings, account session, and preferences. The browser extension normally keeps the key that unlocks the vault only for the current browser session. If you explicitly enable “Keep me unlocked,” that key is stored in the browser profile until you lock Ekko or disable the setting. This device data is used only to provide Ekko's encryption and account features.

Accounts and authentication: an Ekko account is optional. If you sign in with an emailed code, Google, or Apple, Supabase Auth processes your email address, provider identifier, authentication tokens, and the basic profile information returned by that provider. Authentication tokens are stored on your device and sent to Supabase over HTTPS to authenticate account requests. We use this information only to sign you in, secure your account, and provide the account features you request.

Account profile and connections: for signed-in users, Supabase stores your Ekko handle, optional display name, public key, connections, linked messaging handles, and encrypted session-setup records. Your handle and public key are intended to help other people find and encrypt to you. Linked messaging handles are available only where needed to match you with an accepted Ekko connection. Private message content is not part of your Ekko account record.

Directory and discovery: if you claim a directory handle, we store that handle and your public key bundle so other users can find the correct key. If you link a messaging account, we store the platform and its normalized handle or a deterministic hash used for lookup. Automatic discovery is off by default; when you enable it, a lookup sends the platform, a deterministic hash of the relevant account identifier, and the network information inherent in making a request, including your IP address. Using Ekko without an account, a claimed handle, or discovery avoids those account and directory records.

Encrypted key backup: signed-in users may choose to upload an encrypted backup containing their recovery phrase and contact list. The backup is encrypted on the device before upload. The passphrase that opens it is not transmitted to Ekko or Supabase, and the stored backup is designed to be unreadable without that passphrase. A backup can be replaced or deleted from Ekko. Losing the passphrase means we cannot recover the backup for you.

Newsletter: if you subscribe to updates, we store the email address you provide and use it for release news, launch updates, and your install link. Every marketing email includes a one-click unsubscribe. Unsubscribing removes you from the active mailing list; we retain the address on a suppression list so that we can honor that choice and avoid contacting you again.

Bug reports: if you send one, we store what you wrote, the page from which it was submitted, and an email address only if you choose to provide one. Reports are retained only as long as needed to investigate and resolve them.

Website and account analytics and logs: useekko.app and account.useekko.app use self-hosted, cookieless analytics. It records the page visited, referrer origin, browser and device information, a pseudonymous visitor identifier stored in local storage, and selected interactions such as navigation, sign-in method and outcome, profile activation, searches, connection actions, and linked-social actions. After sign-in, account events use a pseudonymous account identifier so we can measure activation and return use. We do not send analytics the email address, profile or social handle, search text, another user's identifier, authentication token, or form content. We do not use cross-site tracking, advertising identifiers, or session replay. We use this information to understand aggregate product performance and improve Ekko, and the analytics data remains on infrastructure we control. Our services also keep short-lived operational logs, such as IP address and request path, for reliability, security, and abuse prevention; those logs are rotated automatically.

Service providers and sharing: our core server runs in an EU datacenter. Supabase provides authentication, account storage, encrypted-backup storage, and the newsletter database. Resend and Amazon SES in Frankfurt deliver account and newsletter email, and Cloudflare protects and delivers useekko.app. Google and Apple process sign-in when you choose their services. These providers receive only the information required for their role and process it under their own terms and our instructions where applicable. The messaging services you use receive Ekko ciphertext and normal delivery metadata under their own privacy policies. We do not sell personal information, share it with data brokers, or use it for personalized advertising.

Retention and your choices: account, profile, connection, and directory information is retained while the associated feature or account remains active, or until you remove it through available controls or ask us to delete it. Encrypted backups remain until you replace or delete them. Security records may be retained longer where reasonably necessary to prevent abuse or comply with law. You may request access, correction, or deletion by emailing [email protected]. If you are in the EU/EEA, consent is the basis for optional marketing email and may be withdrawn at any time; other data is processed as necessary to provide and secure the services you request or comply with legal obligations.

Limited Use: Ekko's use and transfer of information received from Google APIs adheres to the Chrome Web Store User Data Policy, including the Limited Use requirements. Information handled through browser permissions is used only to provide or improve Ekko's user-facing encryption, identity, and account features.

Report a bug

What broke, and where? Leave an email if you want a reply, or stay anonymous.