Privacy Policy

Effective 2026-07-19. This policy describes what the Echo AI Council connector collects, how it is used, and how to delete it.

What we collect

How it is stored

OAuth material is stored, hashed, in Cloudflare Workers KV. Prompts and replies are processed in transit only — this connector keeps no message database. No third-party analytics, advertising, or tracking is used. Note that prompts are answered by third-party AI services (OpenAI, Anthropic, Google, xAI) through the operator's own accounts and are handled by those services under their terms.

How it is used

Solely to provide the service — relaying your prompt to the selected model(s) and returning the reply. We do not sell your data, share it beyond the model services named above, or use it to train models.

Retention & deletion

You can disconnect the connector in your MCP client at any time to revoke access. To delete stored OAuth data, email support@echosforge.com and it will be removed within 30 days.

Security

All traffic is HTTPS. Access requires OAuth 2.1 (PKCE, no plain challenge); tokens are stored only as hashes. Every tool is gated by an operator allowlist — this is a private, operator-only connector.

Contact

Questions or deletion requests: support@echosforge.com.