EchoAnalytics
Privacy Policy
Last updated: 27 August 2026
What EchoAnalytics is
EchoAnalytics is a private analytics dashboard. It collects performance statistics for social media accounts and YouTube channels that their owners have explicitly connected, and presents them as weekly reports. It is operated by a single team for a small number of connected accounts. It is not a consumer product and has no public sign-up.
Google user data we access
When a YouTube channel owner connects their channel, we request two read-only scopes:
youtube.readonly— to read the channel’s own public metadata and its list of uploaded videos (video IDs, titles, publish dates, durations, and lifetime view counts).yt-analytics.readonly— to read the channel’s own YouTube Analytics reports: weekly views, watch time, subscriber counts, likes and comments, and aggregated, anonymous audience demographics (age and gender bands, and viewer country totals) as YouTube itself reports them.
Both scopes are read-only. EchoAnalytics cannot upload, edit, delete, or publish anything on a connected channel, and cannot post comments or change any channel setting. We use these scopes only for the connected channel’s own data. We do not read other channels’ data, and we do not read individual viewers’ personal information — YouTube’s audience reports are aggregated and anonymous before we ever see them.
We requested these scopes because narrower alternatives do not exist: reporting on a channel’s own weekly performance requires the Analytics read scope, and matching those figures to individual videos requires the Data API read scope.
Meta / Instagram data we access
For connected Instagram business accounts we request instagram_basic, instagram_manage_insights, pages_show_list, pages_read_engagement, read_insights, business_management and public_profile. These are used the same way and are also read-only: profile metadata, published posts, and the account’s own insights. We do not post, message, or modify anything.
What we store, and where
We store the statistics we read — metric values, video and post metadata, publish timestamps, and aggregated audience breakdowns — in a private Postgres database hosted by Supabase. We also store the OAuth tokens needed to keep reading, encrypted at rest. We do not store raw provider API responses.
We do notcollect or store: your Google account password, your email contents, your contacts, your Google profile beyond the connected channel’s own identity, or any personal information about your individual viewers or followers.
How we use it
Only to produce the reporting features visible in the dashboard: weekly performance tables, trend charts, and content breakdowns for the account owners themselves.
We do not use this data for advertising, we do not sell it, we do not share it with third parties, we do not use it to build profiles of individuals, and we do not use it to train machine learning or AI models.
Limited Use
EchoAnalytics’ use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically: we limit our use of Google user data to providing the user-facing reporting features described above; we do not transfer this data to others except as required by law; we do not allow humans to read it except where necessary for security or to comply with law, or where the data is aggregated and used for internal operations; and we do not use it for advertising or creditworthiness.
Who can see it
Access is limited to the operators of EchoAnalytics and to the owner of each connected account. The dashboard is password-protected and is not publicly accessible. Our database provider (Supabase) and hosting provider (Vercel) process data on our behalf as infrastructure, under their own terms; no other party receives it.
Retention and deletion
We keep collected statistics for as long as the account remains connected, because the product’s purpose is week-over-week comparison over time.
You can revoke EchoAnalytics’ access to your YouTube channel at any time from your Google Account’s Third-party apps & services page, or for Instagram via your Meta Business settings. Revoking access stops all future collection immediately, but does not by itself erase statistics already collected.
To have previously collected data deleted, email us at the address below. We will delete it and confirm, normally within 30 days. There is currently no self-service deletion button; deletion requests are handled manually by a person.
Children
EchoAnalytics is not directed at children and we do not knowingly collect data about anyone under 13.
Changes
If we change this policy we will update the date at the top of this page.