This Privacy Policy describes how EcoGPT collects, uses, and protects your information when you use our application and related services. By using EcoGPT, you agree to the collection and use of information in accordance with this Privacy Policy.
Data We Collect
Account Information
- Email address (for account creation)
- Display name and username (optional)
- Profile photo (optional)
Usage Data
- Messages you send to EcoGPT
- Images you upload for analysis
- Voice audio and resulting transcripts when you use voice features
- Conversation history
- App usage statistics and analytics
Device Information
- Device type and operating system
- App version
- Crash reports and performance data
How We Use Your Data
To Provide the Service
- Process your messages and provide AI responses
- Analyze images you upload
- Store and sync your conversation history
- Track your environmental impact stats
To Improve the Service
- Analyze usage patterns to improve features
- Debug issues and fix bugs
- Develop new features
Data Sharing
Third-Party Services
- AI providers (OpenRouter and applicable model providers) — for processing AI conversations
- Cloud hosting providers — for hosting, compute, and encrypted content storage
- PlanetScale — for database services
- Supabase — for legacy application services during migration
- Google — for realtime voice processing through Gemini Live and Google sign-in
- Deepgram — for speech-to-text processing
- Cartesia — for text-to-speech processing
- Analytics providers (Tinybird and Mixpanel) — for product analytics and app performance monitoring
- Payment providers (Stripe, Apple, and Google) — for payment and subscription processing
- Advertising partners — conversation context may be shared with third-party advertising services to display relevant sponsored suggestions
Advertising
- We may share conversation context with advertising partners to provide relevant sponsored suggestions
- Sponsored content will be clearly labeled within the app
- You may see suggestions based on the topics discussed in your conversations
- Advertising revenue helps keep EcoGPT free and supports our sustainability mission
We Do NOT
- Sell your personal data to third parties
- Share your personally identifiable information with advertisers
Data Security
Protection Measures
- End-to-end encryption for data in transit
- Cloud hosting and managed database services
- Regular security audits
- Access controls and authentication
Your Rights
You can:
- Access your personal data
- Delete your account and all associated data
- Export your conversation history
- Opt out of analytics collection
Data Retention
Retention Periods
- Account data — retained while your account is active
- Conversation history — retained until you delete it
- Analytics data — account-linked analytics is retained while your account is active and purged on a rolling basis after an account deletion request
- Deleted data — account deletion requests remove account data from production systems; backups are purged on a rolling basis
Children's Privacy
EcoGPT is not intended for children under 13. We do not knowingly collect personal information from children under 13 years of age.
Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy in the app and updating the “Last Updated” date.
Contact Us
If you have questions about this Privacy Policy or your data, please contact us — we read every message.
Advertising Attribution (iOS)
Data We Collect and Use
- A Gravity campaign link contains a click identifier. Vercel also observes ordinary request metadata such as IP address and browser user-agent.
- EcoGPT stores only keyed, one-way values derived from the IP address and a minimal device context (iPhone or iPad and iOS major and minor version). Our attribution database and application logs do not store the raw IP address or full user-agent, although Vercel may retain request metadata under its platform log settings.
- After you authorize tracking through Apple's App Tracking Transparency prompt, the app sends a pseudonymous installation identifier, device family, iOS version, event time, and authorization state to our attribution endpoint.
- If you are signed in, our server may normalize and SHA-256 hash your account email for advertising measurement. The app never supplies plaintext email or its own email hash for attribution.
What We Share with Gravity
- AppInstall, StartTrial, Subscribe, and the once-per-day chat_100_messages_day milestone may include the Gravity click identifier, a pseudonymous installation or account identifier, event time, and a server-derived hashed email when available.
- Subscribe also includes revenue and currency; the chat milestone includes only the count of 100.
- Gravity never receives chat text, prompts, responses, files, or conversation content from this measurement flow.
Your Choice and Retention
- Gravity conversion measurement runs only while iOS reports that tracking is authorized. You may deny or withdraw permission at any time in iOS Settings.
- Unmatched clicks are eligible for up to 45 hours; matched attribution records and active conversion payloads for up to 30 days; completed payloads for 90 days; and failed payloads for 180 days.
- Payload-free keyed deduplication records may remain for up to 730 days. Account deletion or tracking withdrawal removes linked attribution data sooner where applicable; data already sent to Gravity follows Gravity's retention practices.