Skip to content
Echopoint
Flows CI/CD OpenAPI Pricing Docs Blog Have access?
Have access?
Legal

Privacy Policy

Last updated August 21, 2026

Who we are

Echopoint ("Echopoint", "we", "us") provides an API flow automation and testing platform. Echopoint is operated from Québec, Canada. For the personal information described in this policy, Echopoint is the controller.

The person in charge of the protection of personal information under Québec's Act respecting the protection of personal information in the private sector (as amended by Law 25) is the operator of Echopoint. For any privacy question or request, contact privacy@echopoint.dev.

What this policy covers

This policy covers the marketing website at echopoint.dev, the application at app.echopoint.dev, and the API at api.echopoint.dev. It explains what we collect, why we collect it, who processes it on our behalf, how long we keep it, and the rights you have over it.

What we collect, and why

Waitlist

When you join the waitlist, we collect the email address you give us. We use it for one purpose: to contact you about early access to Echopoint. The legal basis is your consent (GDPR art. 6(1)(a)). You can withdraw consent at any time by emailing privacy@echopoint.dev or using the unsubscribe link in any waitlist email, and we will remove your address.

Your account

When your spot opens and you sign in, authentication is handled by Clerk. If you sign in with Google or GitHub, we receive your name, email address, and profile picture from the provider you chose — that provider is the source of this data. If you sign up with email, we collect the email address you enter. We use account data to create and operate your workspace. The legal basis is the contract between us (GDPR art. 6(1)(b)): without an email address, we cannot create your account.

Content you create in Echopoint

Flows, requests, collections, environment variable values, execution results, and the webhook requests your endpoints capture are stored so the service can work. This content may include personal data if you choose to send it — you are responsible for having the right to use any data you send through Echopoint. Environment values are delivered only to the execution that needs them and are not written to logs. The legal basis is the contract between us.

Website analytics

On this marketing site we measure page views, clicks on our own buttons and links, and scroll depth with PostHog, configured so that nothing is stored on your device: no analytics cookies, no localStorage identifiers. Visitors are not identified by default. The legal basis is our legitimate interest (GDPR art. 6(1)(f)) in understanding, in aggregate, how the site is used. If you join the waitlist, we associate your analytics events with the email you submitted so we can manage your early-access enrollment — that association happens only after you submit the form.

Operational logs

The service keeps technical logs (such as request metadata and error traces) to run reliably and to detect abuse. The legal basis is our legitimate interest in keeping the service secure and working.

Cookies

This marketing website does not set analytics cookies and does not store analytics identifiers on your device, which is why it shows no cookie banner. The app at app.echopoint.dev uses cookies that are strictly necessary to keep you signed in.

Who processes data for us

We use four service providers. Each one processes data only to provide its service to us.

ProviderPurposeLocation
Cloudflare, Inc. Content delivery, DNS, and hosting of this website Global edge network (US company)
Clerk, Inc. Authentication and account management for the app United States
PostHog, Inc. Product analytics and the early-access waitlist United States (US Cloud)
Hetzner Online GmbH Servers that run the Echopoint service and store service data Germany and Finland (EU)

Where data goes

The Echopoint service and its data are hosted on Hetzner servers in the European Union (Germany and Finland). Authentication data (Clerk) and analytics data (PostHog US Cloud) are processed in the United States, and Cloudflare operates a global network. For transfers out of the European Economic Area, we rely on the safeguards in each provider's data processing agreement — Standard Contractual Clauses and, where the provider is certified, the EU-U.S. Data Privacy Framework. You can request a copy of the applicable safeguards at privacy@echopoint.dev.

For Québec residents: the providers above store and process personal information outside Québec. We assess these transfers so that your information receives protection equivalent to what Québec law requires.

How long we keep data

  • Waitlist emails — until we invite you, or until you withdraw, whichever comes first.
  • Account data — for as long as your account exists. When you delete your account, we delete the personal data attached to it within a reasonable period after deletion, except where law requires longer retention.
  • Service content — flows, collections, captured webhook requests, and execution history are kept until you delete them or your account.
  • Logs — kept for a short rolling window for security and debugging, then deleted.

Your rights

You can ask us to access, correct, delete, or export the personal information we hold about you, to restrict or object to processing, and to withdraw any consent you gave — withdrawing consent does not affect processing that happened before. Write to privacy@echopoint.dev; we answer within one month.

If you are unsatisfied with our answer, you can complain to your supervisory authority: in Québec, the Commission d'accès à l'information (CAI); elsewhere in Canada, the Office of the Privacy Commissioner of Canada; in the EU/EEA, the data protection authority of your country.

Security

Traffic to and inside Echopoint is encrypted with TLS. Access to production systems is restricted. API keys are scoped, shown once at creation, and can be rotated. Environment values are delivered only to the execution that uses them and are never written to logs.

If something goes wrong

If a confidentiality incident presents a risk of serious harm, we will notify the affected people and the competent authorities (including Québec's CAI) as the law requires, using the email address on your account or waitlist entry.

Children

Echopoint is a tool for developers and businesses. It is not directed to children, and we do not knowingly collect personal information from anyone under 14.

Changes to this policy

When we change this policy, we update the date at the top of this page. If a change materially affects how we handle your personal information, we will notify you by email or in the app before it takes effect.

Contact

Echopoint — Québec, Canada
privacy@echopoint.dev

Echopoint

API flow automation & testing. Chain API calls into visual flows with a real assertions engine, then run them from the cloud, your infra, or CI.

Product

FlowsCI/CDOpenAPI SyncPricingChangelog

Resources

DocumentationGetting startedAPI referenceCLIGitHub ActionBlogCompare

Source

echopoint-cliechopoint-runner
© 2026 Echopoint Privacy Terms echopoint.dev
Opening soon

Join the waitlist

Echopoint Cloud isn’t open to the public yet. Drop your email and we’ll let you in as soon as your spot opens — no credit card, free while in beta.

We’ll only email you about early access. No spam. Echopoint (Québec, Canada) stores your email until launch or until you withdraw — see the Privacy Policy.

✓

You’re on the list

Thanks — we’ll email the moment your spot is ready.