Privacy Policy
How Echo collects, uses, and protects your data on Discord — including every provider it relies on.
1. Overview
Echo ("Echo", "the bot", "we", "us") is an AI-powered Discord application operated by NexaLab. This Privacy Policy explains what information Echo processes when you use it on Discord, why we process it, which providers are involved, and the choices you have.
2. Information we process
Echo only processes the minimum information required to deliver its features:
-
Message content you send to Echo — slash command arguments (e.g. prompts for
/askor/imagine), messages you mention Echo in, and messages you target with context-menu actions such as Translate, Check Fact, or Transcribe. -
Attachments you ask Echo to work on — an audio file for
/transcribe, or an image for/inpaint. Attachments are only fetched when a command needs them. - Server context — the server ID and channel ID where a command is used, so Echo can apply per-server settings (trigger word, prompt, allowlists) and know where to reply.
-
Anonymous, aggregate usage counters — counts of commands and features used per
server (prompts, images, TTS, STT, translations). These contain no message content and no personal
data, and power the
/telemetrycommand.
3. How it is used
- Message content is forwarded to our AI providers solely to generate a response, an image, a translation, a summary, or audio.
- Message content is processed transiently, in memory, and is not retained as a message archive.
- Server and channel IDs are used to enforce settings, permissions, and rate limits.
- Aggregate counters are never linked to an individual user.
- Web searches triggered by research questions use the words of your question as the search query, nothing more.
4. Providers Echo relies on
Echo is a client of the services below. When a feature runs, the relevant content (your prompt, an attachment, or a search query) is sent to the provider that powers that feature. Each provider processes data under its own terms and privacy policy, linked from each card.
Delivers Echo itself: command interactions, messages you target, and attachment downloads via Discord's API and CDN, under Discord's developer terms.
GPT-4o mini via the NAVY API. Short prompts can be load-balanced with Gemini 3.1 Flash Lite and translations go to NAVY first; requests switch to Google, our private server, or NVIDIA when a provider is rate-limited or unavailable. Processed under NAVY's platform terms.
Our own self-hosted AI server (Qwen 2.5 3B) in Germany. It remains a fallback for short prompts and translations when NAVY/Google routes are unavailable — we operate it ourselves.
Gemini 3.5 Flash Lite, Gemini 3.1 Flash Lite, and Gemini image models handle everyday requests, summaries, image generation, and instruction-based image edits. Processed under Google's Privacy Policy and the Gemini API terms.
NVIDIA Nemotron 3 Super 120B acts as the final fallback when Google, NAVY, or private providers are busy, unavailable, or out of quota. Processed under NVIDIA's privacy policy.
Remains a fallback for /imagine when Google image generation is unavailable and powers mask-based /inpaint. For /inpaint, the source image you supply is uploaded to Pixazo together with your prompt, compressed to at most 1 MB.
Powers /tts. Receives the text to read aloud and the selected voice — no other context is sent.
Powers /transcribe. Receives the audio attachment you target, with language auto-detection.
Powers /gif. Receives your search keywords only; results are served from KLIPY's library with its content filter enabled.
Used for /ask research and fact-checking: Echo searches the web with (a summary of) your question and reads public result pages.
Powers /crypto prices. Receives coin names or symbols — never user or server identifiers.
Powers /currency conversions with European Central Bank reference rates. Requests contain no user data at all.
5. What goes where
A per-feature summary of the data that leaves Echo for each provider:
| Feature | Provider | What is sent |
|---|---|---|
/ask, mentions, /persona chat |
Google AI Studio → NAVY/private fallback → NVIDIA NIM | Your prompt and minimal conversation context (routed by size and availability) |
/imagine |
Google AI Studio (Gemini image) → Pixazo fallback | Image prompt only |
/edit-image |
Google AI Studio (Gemini image) | Image prompt + the source image you supply |
/inpaint |
Pixazo | Image prompt + the source image you supply |
/tts |
ElevenLabs | Text to speak + chosen voice |
/transcribe |
FreeTTS | The audio attachment |
/gif |
KLIPY | Search keywords |
/translate, /summarize, /fact-check |
NexaLab private AI → Google AI Studio | The selected message content |
| Web research (automatic) | Google / DuckDuckGo | A search query derived from your question |
/crypto |
CoinGecko | Coin name or symbol |
/currency |
Frankfurter | Nothing user-specific (public rate tables) |
6. Data retention
Echo does not store message content. Prompts and attachments live in memory only as long as the request is in flight. The only durable data is:
- Per-server configuration you or a server admin explicitly set (trigger word, server prompt, channel allowlists, customization);
- Personal instructions you set with
/persona; - Anonymous usage counters.
You can clear persona and configuration at any time with the relevant commands
(e.g. /persona clear, /settings), and opt out of telemetry entirely with
the Opt Out button in /telemetry.
7. Data sharing
We do not sell, rent, or share your personal data with third parties for their own marketing. Data is shared only with the service providers strictly necessary to run the feature you invoked, as described above, or where required by law.
8. Security
All provider requests travel over TLS. API keys are stored only in Echo's server environment and are never exposed to Discord. Access to the infrastructure is restricted to the operators at NexaLab.
9. Children
Echo is not directed at children under the age of 13 (or the minimum age required by Discord's Terms of Service in your region). We do not knowingly collect personal information from children.
10. Your rights & choices
- Opt out of telemetry — use the Opt Out button in
/telemetry(per bot-installed server). - Delete your personal instructions —
/persona clear. - Delete server data — a server admin can reset settings, or remove Echo entirely.
- GDPR & similar rights — depending on your jurisdiction (e.g. the GDPR in the EU), you may have rights to access, correct, or delete personal data, and to object to or restrict processing. Contact us (below) and we will respond promptly.
11. Changes to this policy
We may update this Privacy Policy from time to time — for example when a provider is added, removed, or changes its terms. The latest version is always available at this page, and we will note the effective date of any changes.
12. Contact
Questions about privacy, or requests about your data? Reach us via the Echo support server or through NexaLab.
Questions about your data?
The fastest way to reach the team is the Echo support server.