ECHOSCAN
Continuity
Pending
Visits
···
About Blog

EchoScan Privacy Policy

Last updated: August 30, 2026

This policy explains how EchoScan handles information across the public website, public Scan, Console, Browser Verifier, Report API, and customer integrations. The actual scope depends on the feature a visitor uses, the customer’s plan and configuration, and the request submitted from the customer site.

Scope

This policy applies to websites, Console, APIs, SDKs, and related support services provided directly by EchoScan. When a customer integrates Browser Verifier into its own site, EchoScan processes detection and access-risk data as a technical service provider. The customer also handles account, transaction, and other business information under its own privacy notices.

End users on customer sites do not need an EchoScan account. Developers and customer administrators who sign in to EchoScan Console create account and session data.

Categories of information

Depending on the feature, EchoScan may process:

  • browser and environment signals, including browser and operating-system information, screen and hardware capabilities, language, timezone, fonts, graphics, audio, real-time communication, and automation-related signals;
  • device and continuity information, including server-issued Imprints, Device IDs within a customer authorization scope, seen-before state, access count, first and previous seen times, recent activity, and History;
  • network information, including server-observed IP, country or region results, network consistency, proxy risk, network provider, connection type, and ASN;
  • visit and technical records, including request time, page source, client referrer, errors, performance, security events, and usage records;
  • Console account and session information, including email address, display name, login session, OAuth relationship data, and Workspace membership;
  • customer configuration, including Workspace, Browser Environment, Allowed Origins, and API Key identifiers, prefixes, status, permissions, usage policy, and audit information;
  • plan, usage, and subscription information, including plan, quota, request count, subscription status, billing interval, and payment-flow state.

The plaintext Secret API Key is returned to the customer only after successful creation. The server stores the hash, prefix, and related metadata needed for validation and management. Customers are responsible for storing the plaintext Secret in their own server runtime or secret manager.

Purposes of processing

EchoScan uses this information to run Browser Verifier, issue Imprints, generate Lite or Pro Reports, provide device continuity and History, validate Allowed Origins, protect accounts and APIs, enforce usage and plan limits, support subscriptions, diagnose failures, improve the product, respond to support requests, and detect or handle security and abuse risk.

Aggregated or de-identified information may be used to evaluate service quality, study changes in browser environments, and improve detection reliability. Public documentation does not expose customer Secret API Keys, internal detection evidence, or rule details that could enable circumvention.

Cookies, localStorage, and sessionStorage

Console sign-in uses a session cookie to maintain authentication. Cookie security attributes and lifetime follow the deployed service configuration.

The site uses localStorage for interface settings such as language preference and the developer-documentation theme. Some debugging or page-runtime components use sessionStorage for a temporary tab-scoped session identifier. The public Scan and Browser Verifier also call browser APIs to inspect the environment.

A customer site may use its own cookies or browser storage. The customer controls and explains those practices. This policy does not replace the customer’s cookie or privacy notice.

Necessary service data and optional analytics

EchoScan continues to process necessary service data when optional analytics is declined. This includes data needed to provide core features, maintain authentication and account or Workspace state, enforce permissions and usage limits, operate securely, process billing and subscription state, diagnose failures, and save the privacy choice. Declining optional analytics does not reduce core service functionality.

Optional analytics is disabled until a visitor affirmatively allows it. EchoScan’s single privacy choice controls both providers and is stored in localStorage under echoscan.privacy.consent.v1. The site footer and Console account menu provide a permanent Privacy settings entry. A visitor can reject optional analytics, grant it later, or withdraw a previous grant; withdrawal stops future optional analytics while necessary service data continues.

When allowed, EchoScan uses Google Analytics 4 and PostHog Cloud as optional analytics providers. Google Analytics 4 supports page, session, acquisition, landing-page, country, device, and engagement reporting. EchoScan sends a sanitized page path without URL query or fragment values, selected UTM campaign fields, a referring hostname, and limited scroll, outbound-host, and file-extension engagement data. Google Signals, advertising personalization, user-provided data collection, and advanced consent mode are not enabled. See the Google Privacy Policy.

PostHog Cloud in the European Union supports privacy-limited product analytics, selected feature guidance, sanitized error events, and Session Replay on a limited route allowlist. PostHog data may include a normalized page category, interface language, selected UTM fields, referring host, random Scan attempt identifier, bounded completion or failure stage, duration and count ranges, internal user and Workspace identifiers, plan and membership categories, product-integration milestones, subscription-state categories, release version, and Git revision. Session Replay is sampled on eligible public pages; inputs are masked, sensitive areas are blocked, and Replay stops on public Scan, sign-in, API Key, Browser Environment, Billing, Report, Devices, and other non-allowlisted pages. Network headers and bodies, console logs, canvas, and cross-origin frames are not recorded. See the PostHog Privacy Notice.

Optional analytics does not include email, phone number, real name, display name, Secret API Key, Authorization or Cookie values, Imprint, fingerprint or raw detector output, Device ID, Report content, URL query or fragment values, customer domain or Allowed Origin, request or response headers or bodies, or payment-provider customer, checkout, order, transaction, or subscription identifiers. Retention follows the settings deliberately configured in each provider and the active service plan; the current values are maintained in EchoScan’s production operations record.

Console sign-in and OAuth

Developers and customer administrators can access Console through currently supported sign-in methods. When a person chooses OAuth, the identity provider handles the authentication request under its own policy and sends EchoScan the information needed to establish an account or session. EchoScan uses that information to verify identity, create or link an account, maintain the session, and protect Console.

Ordinary visitors do not sign in to run the public Scan. End users on customer sites also do not need an EchoScan account for Browser Verifier to run.

Sharing and third-party services

EchoScan uses service providers needed for website and API hosting, network and security operations, authentication, email, payment processing, and operational support. Those providers may process information to the extent required to perform the relevant service. Providers can change as infrastructure and product capabilities evolve, so this policy does not present the current implementation as a permanent vendor list.

EchoScan also returns Reports and History to authenticated customers under their instructions, and may disclose information when required for law, security incidents, protection of rights, or a corporate transaction. Secret API Keys stay out of browser code, and an API Key from another Workspace cannot read an Imprint in the customer’s scope.

Data security

EchoScan uses layered technical and organizational measures, including encrypted transport in production, encryption of browser detection payloads, Secret API Key hashing, session and Workspace authorization checks, exact Allowed Origins validation, access controls, logging, and security monitoring.

No system can guarantee absolute security. Customers should protect Secret API Keys, limit server access, rotate or revoke exposed keys promptly, and configure Browser Environments correctly.

Data retention

Different records serve different purposes and can have different retention periods. Device and visit history, accounts and sessions, usage and subscription records, audit data, and security records are retained for the time needed to provide the service, honor customer configuration, resolve disputes, investigate security events, maintain backups, and meet applicable legal requirements.

The published product contract specifies no single automatic-deletion period for every data category. Available deletion, restriction, and request-handling processes depend on the data category, customer configuration, applicable requirements, and current operational capabilities. Customers should evaluate whether EchoScan fits their own retention and compliance requirements.

Requests and choices

People and customers can contact EchoScan about access, correction, deletion, or explanations concerning related information. The available response depends on applicable law, the relationship involved, the data category, and current processes. Identity, Workspace authority, or the customer relationship may need to be verified. An end user of a customer site should usually contact the customer that collected the business information first.

Send privacy and security requests to security@echoscan.org. General questions can be sent to contact@echoscan.org.

Policy updates

EchoScan updates this policy when the product, processing activity, or legal requirements change and revises the date at the top of the page. Material changes will be described through an appropriate site or Console notice. Customers should review this page periodically and describe their EchoScan integration accurately in their own privacy notices.