Echo Privacy Policy
Privacy Policy
1. Controller and contact
Echo is operated by Edwin (“we”). Privacy inquiries may be sent to helper@gleam.com or through the support page.
2. Data and purposes
- Workout data: activity type, time, distance, duration, pace or speed and estimated calories are stored on-device for history, insights, personal records and challenges.
- Precise location and route: used after you start a workout to calculate and display the route and distance. Detailed routes remain on-device; Google Maps Platform may process service data while displaying maps.
- Weather grid: your current location is converted into a KMA grid coordinate and sent to the Korea Meteorological Administration API. Echo does not retain it on a separate server.
- Optional analytics: if enabled, workout lifecycle, activity type and distance/duration ranges are processed by Firebase Analytics. Exact GPS coordinates are not included in Echo analytics events.
- Optional diagnostics: if enabled, Firebase Crashlytics and Performance process crash, performance, device and app information. Maps may process required diagnostics.
- Health Connect import (optional, user-initiated): only when you explicitly run "Import" in Settings, Echo reads past workouts (activity type, start/end time, distance, estimated calories) that other health or fitness apps have written to Android Health Connect, an on-device health data store shared across apps. Echo only reads from Health Connect and never writes to it; imported workouts are then stored on-device the same way as workouts recorded directly in Echo, with duplicate imports prevented by record ID.
- Apple Health (HealthKit) sync, iOS only (optional): only when you allow it in Settings, Echo writes your completed workouts and your height/body mass to Apple Health, and reads heart rate, active energy, step count, detailed running/cycling metrics (pace, power, cadence, and similar), GPS route (HKWorkoutRoute), height, body mass, date of birth and biological sex from Apple Health. Height, body mass, date of birth and biological sex are only processed if you enter them in Settings or allow the Apple Health connection. All values stay in on-device Health storage and Echo's local storage; Echo does not send them to its own servers.
- Optional notifications: if enabled, Firebase Cloud Messaging processes an installation identifier and messaging token.
- Advertising: Google AdMob processes an advertising identifier (IDFA), approximate location (country/region level), ad request/impression/click data and device/app information to serve and measure ads across the app. Personalized ads are only served if you allow App Tracking Transparency (ATT); non-personalized ads may still be served if you don't. Kakao AdFit additionally processes an advertising identifier and ad request data to show a popup ad at launch, but only when your device language is Korean — it is not active for other languages.
- Preferences: theme and consent choices are stored on-device.
Echo currently does not collect account names, phone numbers, addresses, contacts or payment details through the app.
3. Device permissions
- Approximate and precise location for local weather and user-started workouts.
- Location foreground service to keep an active workout visible and recording in the background.
- Notifications for workout status and messages you choose to receive.
- Health Connect exercise, distance and calories (read-only): requested only when you run Import in Settings, to read past workouts from Health Connect. Echo never writes to Health Connect, and you can revoke its access anytime in Android settings or the Health Connect app.
- Apple Health (HealthKit), iOS only: requested only when you allow the connection in Settings. Echo writes completed workouts and height/body mass to Apple Health, and reads heart rate, detailed workout metrics, GPS route, height, body mass, date of birth and biological sex from Apple Health. You can change or revoke access per data type anytime in the iOS Health app.
- App Tracking Transparency (ATT), iOS only: requests permission to use your advertising identifier for personalized ads. The app works the same either way; declining means ads may be shown without personalization. You can change this anytime in iOS Settings → Privacy & Security → Tracking.
The Android app does not request the separate background-location permission.
4. Service providers and international processing
- Google Maps Platform: map display, IP address, device/app information, interactions and diagnostics.
- Google Firebase: optional analytics, diagnostics and messaging information.
- Korea Meteorological Administration/Public Data Portal: weather grid and forecast query parameters.
- Google AdMob: in-app banner ads, advertising identifier, ad request/interaction data.
- Kakao AdFit (Korean-language users only): a popup ad shown at app launch, advertising identifier, ad request data.
Data may be processed in countries where Google or Kakao operate infrastructure and is transmitted using encrypted connections. We do not sell user data or publish it to a social feed. See the Google Privacy Policy and Kakao AdFit operating policy for details.
5. Retention and deletion
- On-device workouts and routes remain until you delete all records in settings or uninstall the app.
- Preferences remain until changed or the app is uninstalled.
- Disabling Firebase options stops future collection; previously processed data follows Google's product retention and deletion procedures.
- Support correspondence is retained only as needed to answer the request, resolve disputes or comply with law.
Echo has no online account to delete.
6. Your choices and rights
You can delete all workouts in Echo settings, disable analytics/diagnostics/notifications separately, change OS permissions, or contact us to request access, correction, deletion or restriction where applicable.
7. Security
Echo uses on-device storage for detailed workouts, disables Android cloud backup, uses HTTPS for external APIs, records routes only during active workouts, keeps optional Firebase collection off by default and excludes detailed coordinates from Echo analytics events.
8. Children
Echo is intended for users aged 18 or older and is not designed for children. Contact us if you believe a child's personal information has been processed.
9. Changes
We will update this page when features, SDKs or laws change and will provide additional in-app notice for material changes.
Change log
- August 3, 2026: Version 1.3 — added advertising (Google AdMob, Kakao AdFit) data, service provider and App Tracking Transparency (ATT) disclosures.
- July 28, 2026: Version 1.2 — added Apple Health (HealthKit) sync data and permission disclosure.
- July 28, 2026: Version 1.1 — added Health Connect import data and permission disclosure.
- July 20, 2026: Version 1.0 initial version.