Skip to main content
Beaux, Inc. | Effective: January 22, 2026 | Last Updated: March 3, 2026
Echo is an email intelligence Chrome Extension operated by Beaux, Inc. It reads your Gmail inbox, extracts key datapoints using AI, and displays them as a live dashboard on your new tab page. This Privacy Policy explains exactly what data we collect, how it is processed, and the rights you have over it. By installing the Echo Chrome Extension and connecting your Gmail account, you agree to the practices described below.

1. What Echo Does

Echo replaces your Chrome new tab page with a live inbox dashboard. It continuously reads incoming Gmail emails, extracts structured datapoints (amounts, dates, names, statuses), and surfaces them in real time — without you opening a single thread. The extension communicates exclusively with Echo’s own servers. It does not interact with any other website you visit and does not inject scripts into third-party pages.

2. Information We Collect

2.1 Information You Provide

  • Email address — for account creation and authentication
  • Payment information — processed by Stripe; we never store full card numbers or CVV codes
  • Gmail OAuth token — used to access your inbox with read-only permissions; revocable at any time

2.2 Information We Process Automatically

  • Email content — full email bodies are sent to our AI pipeline to extract datapoints. Raw email content is never stored after processing is complete; it is processed in memory and discarded immediately
  • Email metadata — sender, recipient, subject line, date, and Gmail labels
  • Extracted datapoints — dates, amounts, names, statuses, and other structured data derived from your emails; these are stored and power your dashboard
  • Usage data — dashboard views, Rules created, sync events, and feature interactions
  • Technical data — browser type, IP address, and operating system, collected via Google Analytics

2.3 What We Do NOT Collect

  • We do not store raw email content
  • We do not collect your browsing history outside of Echo
  • We do not track the websites you visit
  • We do not collect keystrokes, mouse movements, or screen activity

3. How We Use Your Information

  • Provide the Service — process emails, extract datapoints, and generate your live dashboard
  • Process payments — manage billing and subscriptions via Stripe
  • Improve accuracy — analyze anonymized usage patterns to improve AI extraction quality; no email content is used for this purpose
  • Communicate with you — account notifications, product updates, and support responses
  • Ensure security — detect and prevent fraud, abuse, or unauthorized access

4. AI Processing & Data Handling

4.1 How It Works

When you create a Rule — a prompt that defines what data to extract — Echo reads the relevant emails from your Gmail and sends full email content to our AI provider for processing. Only the resulting structured datapoints are stored. Raw email content is processed in memory and discarded immediately after extraction completes.

4.2 Our AI Provider

  • Provider: Anthropic (Claude API)
  • What is sent: Full email content for emails matching your active Rules
  • Anthropic data retention: Anthropic does not train models on API customer data. Email content is not retained by Anthropic beyond the duration of the API call
  • Encryption in transit: All data sent to Anthropic is encrypted via HTTPS/TLS

4.3 Third-Party Service Providers

We share limited data with trusted vendors solely to operate Echo:
VendorPurposeReceives email data?
AnthropicAI extraction via Claude APIYes, transiently
StripePayment processingNo
AWS (US-East)Infrastructure and database hostingYes, encrypted at rest
Google AnalyticsAggregated, anonymized usage statisticsNo
We never sell your data to third parties, share email content with advertisers, or use your information for any purpose beyond Echo’s core functionality.

5. Chrome Extension Specifics

5.1 Permissions Used

PermissionWhy it’s needed
identity / Gmail OAuthTo access your Gmail inbox with read-only permissions
storageTo cache your dashboard data locally in Chrome Storage
tabs / newtabTo display the Echo dashboard on every new tab
No permissions beyond those listed above are requested. We do not request access to your browsing history, bookmarks, or any other Chrome data.

5.2 Local Chrome Storage

The extension stores your dashboard cache locally in Chrome Storage only. This data never leaves your device except to sync with Echo’s own servers. It is not accessible to other extensions or websites.

5.3 Remote Code

Echo makes API calls to Anthropic’s Claude API and Echo’s own backend to process emails and retrieve dashboard data. No executable code is loaded remotely into the extension itself; all extension logic is bundled in the published package.

5.4 New Tab Override

Echo replaces your Chrome new tab page with your inbox dashboard. This is the extension’s sole interaction with your browser UI. It does not modify any other browser behavior.

6. Data Storage & Security

6.1 What We Store

  • Extracted datapoints — stored encrypted in PostgreSQL on AWS (US-East)
  • Email content — not stored; processed in memory and discarded after extraction
  • OAuth tokens — stored encrypted; never logged in plain text
  • Account data — email address, billing history, and settings
  • Cache data — temporary session and job data stored in Redis; automatically expires and is never written to long-term storage

6.2 Security Measures

  • All data in transit is encrypted via HTTPS/TLS
  • Data at rest is encrypted at the database level on AWS
  • Access to production systems is limited to authorized personnel and fully logged
  • Gmail access is strictly read-only — Echo cannot send, delete, or modify your emails

6.3 Data Retention

  • Active accounts: Data retained as long as your account is active
  • Deleted accounts: All data permanently removed from production systems within 30 days of deletion
  • Backups: Retained for 30 days for disaster recovery, then permanently deleted
  • Server logs: Retained for 90 days for security and debugging purposes

7. Your Rights & Choices

7.1 Access & Control

You can:
  • View all extracted datapoints in your Echo dashboard
  • Revoke Gmail access at any time via Google Account Security Settings or Echo Settings — this immediately stops all inbox processing
  • Delete your account in Echo Settings; all data is permanently removed within 30 days
To request a copy of your data, contact i@beau.to.

7.2 GDPR Rights (EU Users)

If you are in the European Union, you have the right to:
  • Access your personal data
  • Correct inaccurate data
  • Request erasure (“right to be forgotten”)
  • Restrict or object to processing
  • Receive your data in a portable format
  • Withdraw consent at any time
Contact i@beau.to to exercise any of these rights. We will respond within 30 days. Legal basis for processing:
  • Consent — you authorize Gmail access when connecting your account
  • Contractual necessity — to deliver the Echo service you have signed up for
  • Legitimate interests — to improve service quality, ensure security, and prevent fraud

7.3 CCPA Rights (California Users)

If you are a California resident, you have the right to know what personal information we collect and how it is used, to request deletion, and to opt out of data sales. We do not sell your personal information. Contact i@beau.to to exercise these rights. We will respond within 45 days.

8. Google API Services Compliance

Echo’s use of Gmail data adheres to the Google API Services User Data Policy, including all Limited Use requirements:
  • Echo uses Gmail data exclusively to provide the email intelligence features you have requested
  • Gmail data is not transferred to third parties except to Anthropic for AI extraction, which is necessary to provide the service
  • Gmail data is never used for advertising purposes
  • No Echo employee reads your Gmail data, except to investigate a specific security or compliance issue, or with your explicit consent

9. Cookies & Tracking

We use essential cookies for authentication and session management — these cannot be disabled without breaking core functionality. We also use Google Analytics cookies to understand aggregate usage patterns; you can block these via your browser settings without affecting Echo’s core features.

10. Children’s Privacy

Echo is not intended for users under 13 years of age (or 16 years in jurisdictions where a higher minimum age applies). We do not knowingly collect personal information from children. If you believe a child has provided information to Echo, contact i@beau.to and we will delete it immediately.

11. International Data Transfers

Echo is operated from the United States and data is stored on AWS infrastructure in the US-East region. If you access Echo from outside the United States, your data will be transferred to and processed in the United States. We ensure appropriate safeguards are in place for international transfers, including for users in the EU and UK.

12. Data Breach Notification

In the event of a data breach affecting your personal information, we will:
  • Notify affected users within 72 hours
  • Report to relevant authorities as required by applicable law
  • Provide clear guidance on how to protect your account

13. Open-Source Notice

Echo’s core engine is open-source and available on GitHub. This Privacy Policy applies to the hosted Chrome Extension version of Echo. If you choose to self-host Echo using the open-source codebase, you are responsible for your own data handling practices and this policy does not apply to your self-hosted instance.

14. Changes to This Policy

We may update this Privacy Policy from time to time. If changes are material, we will notify you by email at least 30 days before they take effect and post a prominent notice in the extension. Continued use of Echo after changes take effect constitutes acceptance of the updated policy.

15. Contact Us

Email: i@beau.to Address: Beaux, Inc., 2261 Market Street #4410, San Francisco, CA 94114 Response time: We aim to respond within 5 business days

Appendix: Sub-Processors

Sub-ProcessorLocationPurpose
Anthropic, PBCUnited StatesAI datapoint extraction
Amazon Web ServicesUnited States (US-East)Infrastructure, database, and storage
Stripe, Inc.United StatesPayment processing
Google LLCUnited StatesAnalytics (anonymized)

Version 1.0 | Last reviewed: March 3, 2026