Privacy Policy

This policy describes what the FeedEcho hosted service at feedecho.net collects, stores, and does with your data. Last updated: September 20, 2026.

FeedEcho is operated by Jason Crabtree, Winchester, Virginia, United States. For privacy questions or data requests, email support@feedecho.net.

What we collect and why

DataWhy we need it
Email addressAccount identity, verification, password reset, and operational alerts about your feeds.
PasswordStored only as a salted scrypt hash. Never in plain text.
Feed URLsThe feeds you ask us to watch, and a cursor (last seen item) per feed so posts are not duplicated.
Destination credentialsTokens, app passwords, webhook URLs, and SMTP credentials for the accounts you connect (Mastodon, Bluesky, micro.blog, Matrix, Discord, Telegram, email, webhooks). Required to post on your behalf; nothing else is done with them. They are encrypted at rest.
Echo configurationYour templates, filters, and delivery settings.
Post historyWhich feed items were delivered where, when, and with what outcome — needed for retries, duplicate prevention, and failure diagnosis.
Server logsRequest paths, status codes, and timestamps for debugging and abuse prevention. Paths only — query strings (which could contain tokens) are never logged.

Legal basis for processing (GDPR)

If you are in the European Economic Area or the UK, we process your personal data on these bases:

We do not rely on consent as a legal basis — we process on contract and legitimate interests as described above, and we do not sell personal data.

Your privacy rights

Depending on where you live, you have rights over your personal data, which we honour through the controls below:

California residents: you have the right to know what personal data we collect, to request its deletion, and to non-discrimination for exercising your rights. We do not sell personal data. Email support@feedecho.net to exercise these rights.

What we don't do

Where your data lives

All account data is stored in a Postgres database on a server we operate in the United States (with encrypted offsite backups of that database). Destination credentials are encrypted at rest. Traffic is HTTPS with HSTS. Sessions are signed, HttpOnly, SameSite cookies; logging out or resetting your password invalidates existing sessions immediately. Every feed, account, setting, and history row is scoped to your account at the query level.

Breach notification: if we learn that your personal data has been compromised, we will notify affected users and, where required, the relevant authorities.

Who else sees data

How long we keep things

Your controls

Contact

Privacy questions or data requests: email support@feedecho.net or reply to any email this service sent you.