Privacy Policy
This policy describes what the FeedEcho hosted service at feedecho.net collects, stores, and does with your data. Last updated: September 20, 2026.
FeedEcho is operated by Jason Crabtree, Winchester, Virginia, United States. For privacy questions or data requests, email support@feedecho.net.
What we collect and why
| Data | Why we need it |
|---|---|
| Email address | Account identity, verification, password reset, and operational alerts about your feeds. |
| Password | Stored only as a salted scrypt hash. Never in plain text. |
| Feed URLs | The feeds you ask us to watch, and a cursor (last seen item) per feed so posts are not duplicated. |
| Destination credentials | Tokens, app passwords, webhook URLs, and SMTP credentials for the accounts you connect (Mastodon, Bluesky, micro.blog, Matrix, Discord, Telegram, email, webhooks). Required to post on your behalf; nothing else is done with them. They are encrypted at rest. |
| Echo configuration | Your templates, filters, and delivery settings. |
| Post history | Which feed items were delivered where, when, and with what outcome — needed for retries, duplicate prevention, and failure diagnosis. |
| Server logs | Request paths, status codes, and timestamps for debugging and abuse prevention. Paths only — query strings (which could contain tokens) are never logged. |
Legal basis for processing (GDPR)
If you are in the European Economic Area or the UK, we process your personal data on these bases:
- Performance of a contract (Art. 6(1)(b) GDPR): everything needed to provide the service you signed up for — your account, feeds, echoes, destination credentials, and post history.
- Legitimate interests (Art. 6(1)(f) GDPR): securing the service, preventing abuse, and debugging. Server logs fall under this; they are minimal and kept only briefly.
We do not rely on consent as a legal basis — we process on contract and legitimate interests as described above, and we do not sell personal data.
Your privacy rights
Depending on where you live, you have rights over your personal data, which we honour through the controls below:
- Access — your dashboard shows your feeds, echoes, and full delivery history.
- Export / portability — export your configuration from the dashboard at any time.
- Rectification — edit or reconnect your feeds, accounts, and echoes in the dashboard.
- Deletion — delete any feed, account, or echo, or delete your entire account from Settings (this removes all of your data, including post history).
- Restriction and objection — email support@feedecho.net and we will restrict or stop processing where the law requires.
- Complaint — if you are in the EEA/UK and are not satisfied, you have the right to lodge a complaint with your local data-protection supervisory authority.
California residents: you have the right to know what personal data we collect, to request its deletion, and to non-discrimination for exercising your rights. We do not sell personal data. Email support@feedecho.net to exercise these rights.
What we don't do
- We don't sell, rent, or share your data. There is no advertising.
- Feed content is fetched, filtered, posted, and discarded — it is not archived. Only item identifiers and delivery outcomes are kept.
- No analytics, tracking scripts, or third-party browser requests run on these pages.
- No payment data: billing is handled by Stripe, which processes your card directly — card numbers never touch our servers.
Where your data lives
All account data is stored in a Postgres database on a server we operate in the United States (with encrypted offsite backups of that database). Destination credentials are encrypted at rest. Traffic is HTTPS with HSTS. Sessions are signed, HttpOnly, SameSite cookies; logging out or resetting your password invalidates existing sessions immediately. Every feed, account, setting, and history row is scoped to your account at the query level.
Breach notification: if we learn that your personal data has been compromised, we will notify affected users and, where required, the relevant authorities.
Who else sees data
- Your connected platforms (Mastodon, Bluesky, micro.blog, your Matrix homeserver, Discord, your email provider) receive exactly the posts you configure — nothing else.
- Email delivery for verification and password-reset mail goes through a transactional email provider; it processes the message (and your address as recipient) to deliver it.
- Payment processing is handled by Stripe, which processes your card directly for subscriptions and refunds.
- Uptime monitoring periodically requests the public health endpoint from outside the server; it does not involve your account data.
- Nothing else, unless required by law.
How long we keep things
- Account and configuration data: while your account exists.
- Post history and delivery outcomes: retained with the feed/echo records they belong to, so your posting record and retry state survive. Deleting a feed or echo removes access to its history; full account deletion (below) removes everything.
- Verification and password-reset tokens: single-use, expire in 24 hours, stored only as hashes.
- Server logs: rotated automatically and kept briefly.
Your controls
- Delete individual feeds, connected accounts, or echoes from the dashboard at any time.
- Revoke any destination token at its source platform (Mastodon, Bluesky, micro.blog, or Matrix settings) — we stop being able to post immediately.
- Export your data: the dashboard shows your feeds, echoes, and full delivery history.
- Delete your account entirely from Settings (password-confirmed) — this removes your account and all of its data, including post history.
Contact
Privacy questions or data requests: email support@feedecho.net or reply to any email this service sent you.