This Privacy Policy describes how EcoGPT collects, uses, and protects your information when you use our application and related services. By using EcoGPT, you agree to the collection and use of information in accordance with this Privacy Policy.
Data We Collect
Account Information
- Email address (for account creation)
- Display name and username (optional)
- Profile photo (optional)
Usage Data
- Messages you send to EcoGPT
- Images you upload for analysis
- Files you upload for processing
- Voice audio and transcripts when you use voice features
- Conversation history
- App usage statistics and analytics
Device Information
- Device type and operating system
- App version
- Crash reports and performance data
How We Use Your Data
To Provide the Service
- Process your messages and provide AI responses
- Analyze images you upload
- Store and sync your conversation history
- Track your environmental impact stats
To Improve the Service
- Analyze usage patterns to improve features
- Debug issues and fix bugs
- Develop new features
Data Sharing
Third-Party Services
Depending on the feature you use and the provider that serves the request, we send prompts, messages, and relevant conversation context to AI providers; images or signed image links for image analysis or editing; image prompts and editing instructions for image generation or editing; files or signed file links for document conversion; live or recorded audio, or signed audio links, for transcription; and text for speech synthesis. We also send selected message text and conversation summaries to Cloudflare Workers AI to create retrieval embeddings, and search queries or requested URLs to web-search and page-reading providers.
When you use account email, weather, push notification, connected-service, or custom MCP features, we also send the email address and verification or reset message, named location or coordinates, notification token and notification content, or queries and requested content needed to complete the action to the provider for that feature.
- AI processing (Google Cloud) — hosts our primary dedicated model deployment in the europe-north1 region in Hamina, Finland; when that deployment is unavailable, requests use the OpenRouter fallback described below
- OpenRouter — receives prompts and relevant conversation content and routes them to model providers when our primary deployment is unavailable, including all affected requests during an outage; also analyzes uploaded images when configured
- Speech, image, and document providers — for turning what you say into text, generating spoken replies, generating and editing images, and converting files you upload
- Web search and page reading — for running searches you ask for and reading pages you link to
- Infrastructure and data storage — for application hosting and compute, file storage, database services, and text embeddings
- Account and notification services — for sending verification and password-reset emails, delivering push notifications, and looking up weather when you ask for it
- Payment processors (Stripe, Apple, and Google) — Stripe for web, Apple for iOS, and Google Play for Android payment and subscription processing
- Analytics — for product analytics and application performance monitoring
- Services you connect yourself — when you connect an account or a custom MCP server, it receives the queries and content needed to retrieve information or make the changes you ask for
- Advertising partners — we send recent messages, or the current prompt and response, to select and display sponsored suggestions. Depending on the partner they also receive a pseudonymous user and conversation identifier, IP address, user agent, and country, and when configured a hashed email address. One partner's software runs on your device, so it receives your IP address and user agent directly, and on Android the advertising ID
The companies behind each category above are named, with what they do, in our subprocessor list.
We share data with each provider only as needed to provide the feature it serves. For requests routed through OpenRouter, we select providers that do not use prompts or outputs to train models. This restriction does not itself guarantee zero data retention; providers may retain data for service delivery or security under their applicable terms. Providers processing Google user data, including content derived from it, are subject to the additional Limited Use restrictions below.
Advertising
- We may share recent conversation content and the identifiers described above with advertising partners to provide relevant sponsored suggestions
- Sponsored content will be clearly labeled within the app
- You may see suggestions based on the topics discussed in your conversations
- Advertising revenue helps keep EcoGPT free and supports our sustainability mission
We Do NOT
- Sell your personal data to third parties
- Train foundational models on your conversations or other content you provide
Google user data and Limited Use
EcoGPT's use of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
When you connect a Google service (such as Gmail, Google Calendar, Google Drive, or Google Contacts), EcoGPT uses that data solely to provide the features you ask for in your own conversations — for example, finding an email you described or adding an event you requested. Google user data is never used to develop, improve, or train generalized artificial-intelligence or machine-learning models; never sold; never used for advertising; and never transferred to third parties except as needed to provide those user-requested features, for security, or to comply with law. Relevant Google data and your requests are transmitted to the AI provider serving the request to generate responses, including Google Cloud for our primary deployment or OpenRouter and its serving model providers when that deployment is unavailable. Other AI providers receive it only when needed for a feature you request. OpenRouter requests exclude providers that train on prompts or outputs; this setting does not itself guarantee zero retention. You can disconnect a Google service at any time from the Apps page, which revokes EcoGPT's access. Google data included in your chats remains in your chat history until you delete those chats or your account.
Data Security
Protection Measures
- Encryption in transit using HTTPS/TLS
- Secure cloud storage with our infrastructure providers
- Regular security audits
- Access controls and authentication
Your Rights
You can:
- Access your personal data
- Delete your account, your conversations, and your files
- Export your conversation history
Data Retention
Retention Periods
- Account data — retained while your account is active
- Conversation history — retained until you delete it
- Analytics data — retained while it remains useful for operating and improving the service; deleted upon verified account deletion
- Deleted data — deletion begins immediately and completes across our systems within 30 days
Children's Privacy
EcoGPT is not intended for children under 13. We do not knowingly collect personal information from children under 13 years of age.
Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy in the app and updating the “Last Updated” date.
Contact Us
If you have questions about this Privacy Policy or your data, please contact us — we read every message.