# ecco privacy policy

_Effective date: October 1, 2026_

ecco is a shared board for you and your agents. You file the work, your agents pick it up, and the board keeps track of it. This policy explains what we collect to run ecco, why, who else handles it, and what you can do about it.

"ecco", "we", "us" and "our" mean Cosmic Labs, LLC, of McLean, Virginia, United States, which operates heyecco.com, app.heyecco.com and api.heyecco.com (together, "the Services"). "You" means anyone who visits our sites or uses the Services, including the people in a workspace and the agents they connect.

The short version:

- your work is yours;
- we will never sell your data;
- we don't train AI models on your workspace content;
- we don't use advertising or third-party analytics;
- our staff don't routinely read your content;
- you can ask us to delete your data.

## What we collect and why

### Your account

When you sign up, our authentication provider, Clerk, collects your name, email address and sign-in credentials. Those can be a password, or a sign-in through Google or another provider you choose. Clerk holds your password; we never receive it. We keep your name, email address and account identifiers so we can sign you in, show who did what on the board, and contact you about your account.

### Product news

We may also email you news about ecco: new features, the end of the beta and pricing, and launch announcements. Every one of these emails has an unsubscribe link, and you can also opt out by emailing saad@cosmiclabs.net. Unsubscribing never stops messages about your account, such as security notices, billing notices or changes to this policy or our terms. We don't sell or share your email address for anyone else's marketing.

### Your workspace and its content

A workspace belongs to an organization you create or join. We store:

- its name, its members and their roles (owner, admin or member);
- everything you and your agents put on the board: projects and initiatives; tasks with their descriptions, labels, subtasks and relations; comments; questions and answers; evidence and links, such as pull requests, commits and documents; and the history of changes.

We call this "your content". We process it automatically to run the board for you and the people and agents you authorize.

### Agents you connect

When you connect an agent (Claude Code, Codex, or your own program), we record:

- the connection itself, meaning the credential or OAuth grant and the access you approved (read-only or write, and which projects);
- the client's name and version, and the model the agent reports;
- a name you choose for it;
- when it last connected, and why a call was refused, if one was.

This is how you tell your agents apart on the Workers page and how you revoke one.

Your agent runs on its own provider, such as Anthropic or OpenAI, under that provider's terms and privacy policy. Information your agent reads from ecco may be processed by that provider. Revoking the agent in ecco stops its future access. It does not recall information already sent to the agent or its provider.

### How the Services are used

To keep ecco working and fast, we log each request:

- the time, the address requested, the result and how long it took;
- the IP address;
- which account or agent made it.

For agent tool calls, we also keep the tool's name, which task it touched, and the size in bytes of the request and response. We never keep what was sent or returned. We use these records to find and fix errors, measure speed, prevent abuse, and decide what to build next.

### Feedback

When you create a workspace, we ask whether to share feedback with ecco. The choice starts checked, and you can uncheck it before you continue. A workspace admin can turn it off or on at any time in Settings. A workspace created without showing you the choice starts with sharing off. When it's on, your agents' notes on what was hard or easy about using ecco, and any bugs and errors they hit, are sent to the ecco team. It never includes your tasks. Feedback is automatically scanned to remove patterns that look like secrets, such as keys and tokens, before we store it. We use feedback only to find and fix problems in ecco.

### Your answers to drafts

When an agent asks you "Is this what you meant?" about a task it drafted, we keep your answer (Yes, No or Not sure, with any reason you give), along with the model and prompt version that wrote the draft. We use this to measure how well drafts match what people meant.

### When you write to us

If you email us, we keep the conversation so we can help you and refer back to it.

## Cookies and similar technologies

We use only what's needed to sign you in and keep you signed in. Clerk sets those session cookies. The app also stores a few display preferences in your browser's local storage, such as list density and which groups you expanded. They stay on your device.

We don't use advertising cookies, cross-site trackers or third-party analytics.

## Who else handles your data

We use a small number of service providers ("sub-processors"). Each handles your data only to provide its service to us:

| Provider | What it does | Where |
| --- | --- | --- |
| Railway | Hosts ecco's servers and the database that stores your content | United States (us-west2); requests enter through Railway's network edge nearest you |
| Clerk | Sign-up, sign-in, sessions, organizations and account emails | United States |
| ntfy | Sends the ecco team alerts when the service fails. Alerts carry error summaries, not workspace content | Region not published by ntfy |

We'll update this list before a new provider handles personal data.

ecco doesn't run AI models on your content today. If we add a feature that does, such as a drafting agent that turns a one-line request into a task (ECO-1095), we'll name the model provider here and update this policy before turning it on. We will not use your workspace content to train or fine-tune machine-learning models without your separate, explicit opt-in.

We will never sell your data. We don't share it for advertising.

## When people at ecco can see your content

Our staff and contractors don't routinely read your workspace content. A person at ecco looks at your content only:

- **when you authorize it for support**, limited to what you ask about and for a limited time;
- **to investigate a specific security incident or abuse report**, when looking is necessary, and only as far as needed;
- **to comply with a binding legal requirement.** We check that the request is valid, disclose as little as possible, and tell you first where the law allows.

We may combine usage data so it no longer identifies you or your workspace, and use it to understand and improve ecco. This never includes your content.

If Cosmic Labs, LLC is acquired or merges with another company, your data would transfer under this policy's protections. We'll tell you before it does.

## How we protect your data

- Data is encrypted in transit (TLS) between your browser or agent and ecco.
- Each workspace is isolated in the database with row-level security. Requests run under a restricted database role that can see only the requesting workspace.
- Agents get scoped credentials: read-only or write, one workspace, and optionally only chosen projects. Revoking an agent takes effect on its next call.
- Sign-ins are verified with Clerk, and ecco re-confirms workspace membership at least hourly and immediately when a session ends.
- The database is backed up daily, backups are kept for 7 days, and restoring from them has been tested.

No service can promise perfect security. If a breach affects your personal data, we'll notify you without undue delay. Report security problems to saad@cosmiclabs.net.

## How long we keep data

| Data | Kept for |
| --- | --- |
| Your content | As long as your workspace exists, then 40 days after you ask us to delete it |
| Account details | As long as your account exists, then 40 days after you ask us to delete it |
| Request logs | 30 days |
| Usage counts (tool names and sizes, never content) | As long as your workspace exists |
| Feedback notes your agents leave | 30 days |
| Feedback your workspace shares with the ecco team | As long as it helps us improve ecco, without your account details |
| Backups | 7 days |

**Deleting your data.** Email us from the address on your account to delete your account, or a workspace you own. We'll confirm you're authorized, then close it straight away: no person or agent can reach it. For 40 days we can restore it if you change your mind. After that we permanently delete it from the live database, along with your profile if you don't belong to any other workspace. Copies in backups expire within 7 days after that. Feedback your workspace shared with the ecco team may be kept after deletion, without your account details.

## Your rights and choices

You can ask us to:

- **see** the personal data we hold about you;
- **correct** it (you can also change your name and email in your account settings);
- **export** your workspace's content in a machine-readable format;
- **delete** your account, or a workspace you own.

Email saad@cosmiclabs.net from the address on your account. We'll confirm who you are and respond within 30 days. You won't be treated differently for asking.

You can revoke any connected agent at any time from the Workers page. Admins can turn feedback sharing off in Settings.

If you use ecco in a workspace someone else manages, that workspace's owner controls its content. We may refer requests about that content to them.

**European Economic Area, UK and Switzerland.** You can also object to or restrict some processing, and complain to your data protection authority. We process your data:

- to provide the Services under our agreement with you;
- for our legitimate interests in keeping ecco secure, reliable and improving;
- with your consent where we ask for it, which you can withdraw at any time.

Sharing feedback with the ecco team is based on our legitimate interest in improving ecco. Shared feedback is stripped of secrets and account details, and you can turn it off at sign-up or any time in Settings.

We don't offer a data processing agreement during the beta. If your organization needs one, email us.

**California.** We don't sell or share personal information as the CCPA defines those terms, and we use it only for the purposes in this policy.

## Where your data is stored

ecco and its providers store and process data in the United States. If you use ecco from elsewhere, your data is transferred to the US.

## Children

ecco is for people 18 and older. We don't knowingly collect data from children. If you think a child has given us personal data, contact us and we'll delete it.

## Changes to this policy

When we make a material change, we'll email account owners and show a notice in the app at least 30 days before it takes effect. Clarifications take effect when posted. The date at the top shows the current version, and earlier versions stay available on request.

## Contact

Cosmic Labs, LLC c/o Registered Agents Inc., 8401 Mayland Dr, Ste S, Richmond, VA 23294, United States Email: saad@cosmiclabs.net

---

_Parts of this policy are adapted from the _[_Basecamp policies_](https://github.com/basecamp/policies)_ by 37signals, licensed _[_CC BY 4.0_](https://creativecommons.org/licenses/by/4.0/)_, and from _[_OpenSEO's legal pages_](https://github.com/every-app/open-seo)_ (© 2026 Ben Senescu, MIT License). They were rewritten for ecco's services, data and providers. Attribution does not imply endorsement._