ECHOSCAN
UNQ
STB
#···
About Blog

EchoScan Privacy Policy

Last updated: July 30, 2026

This policy explains how EchoScan handles information across the public website, public Scan, Console, Browser Verifier, Report API, and customer integrations. The actual scope depends on the feature a visitor uses, the customer’s plan and configuration, and the request submitted from the customer site.

Scope

This policy applies to websites, Console, APIs, SDKs, and related support services provided directly by EchoScan. When a customer integrates Browser Verifier into its own site, EchoScan processes detection and access-risk data as a technical service provider. The customer also handles account, transaction, and other business information under its own privacy notices.

End users on customer sites do not need an EchoScan account. Developers and customer administrators who sign in to EchoScan Console create account and session data.

Categories of information

Depending on the feature, EchoScan may process:

  • browser and environment signals, including browser and operating-system information, screen and hardware capabilities, language, timezone, fonts, graphics, audio, real-time communication, and automation-related signals;
  • device and continuity information, including server-issued Imprints, Device IDs within a customer authorization scope, seen-before state, access count, first and previous seen times, recent activity, and History;
  • network information, including server-observed IP, country or region results, network consistency, proxy risk, network provider, connection type, and ASN;
  • visit and technical records, including request time, page source, client referrer, errors, performance, security events, and usage records;
  • Console account and session information, including email address, display name, login session, OAuth relationship data, and Workspace membership;
  • customer configuration, including Workspace, Browser Environment, Allowed Origins, and API Key identifiers, prefixes, status, permissions, usage policy, and audit information;
  • plan, usage, and subscription information, including plan, quota, request count, subscription status, billing interval, and payment-flow state.

The plaintext Secret API Key is returned to the customer only after successful creation. The server stores the hash, prefix, and related metadata needed for validation and management. Customers are responsible for storing the plaintext Secret in their own server runtime or secret manager.

Purposes of processing

EchoScan uses this information to run Browser Verifier, issue Imprints, generate Lite or Pro Reports, provide device continuity and History, validate Allowed Origins, protect accounts and APIs, enforce usage and plan limits, support subscriptions, diagnose failures, improve the product, respond to support requests, and detect or handle security and abuse risk.

Aggregated or de-identified information may be used to evaluate service quality, study changes in browser environments, and improve detection reliability. Public documentation does not expose customer Secret API Keys, internal detection evidence, or rule details that could enable circumvention.

Cookies, localStorage, and sessionStorage

Console sign-in uses a session cookie to maintain authentication. Cookie security attributes and lifetime follow the deployed service configuration.

The site uses localStorage for interface settings such as language preference and the developer-documentation theme. Some debugging or page-runtime components use sessionStorage for a temporary tab-scoped session identifier. The public Scan and Browser Verifier also call browser APIs to inspect the environment.

A customer site may use its own cookies or browser storage. The customer controls and explains those practices. This policy does not replace the customer’s cookie or privacy notice.

Console sign-in and OAuth

Developers and customer administrators can access Console through currently supported sign-in methods. When a person chooses OAuth, the identity provider handles the authentication request under its own policy and sends EchoScan the information needed to establish an account or session. EchoScan uses that information to verify identity, create or link an account, maintain the session, and protect Console.

Ordinary visitors do not sign in to run the public Scan. End users on customer sites also do not need an EchoScan account for Browser Verifier to run.

Sharing and third-party services

EchoScan uses service providers needed for website and API hosting, network and security operations, authentication, email, payment processing, and operational support. Those providers may process information to the extent required to perform the relevant service. Providers can change as infrastructure and product capabilities evolve, so this policy does not present the current implementation as a permanent vendor list.

EchoScan also returns Reports and History to authenticated customers under their instructions, and may disclose information when required for law, security incidents, protection of rights, or a corporate transaction. Secret API Keys stay out of browser code, and an API Key from another Workspace cannot read an Imprint in the customer’s scope.

Data security

EchoScan uses layered technical and organizational measures, including encrypted transport in production, encryption of browser detection payloads, Secret API Key hashing, session and Workspace authorization checks, exact Allowed Origins validation, access controls, logging, and security monitoring.

No system can guarantee absolute security. Customers should protect Secret API Keys, limit server access, rotate or revoke exposed keys promptly, and configure Browser Environments correctly.

Data retention

Different records serve different purposes and can have different retention periods. Device and visit history, accounts and sessions, usage and subscription records, audit data, and security records are retained for the time needed to provide the service, honor customer configuration, resolve disputes, investigate security events, maintain backups, and meet applicable legal requirements.

The published product contract specifies no single automatic-deletion period for every data category. Available deletion, restriction, and request-handling processes depend on the data category, customer configuration, applicable requirements, and current operational capabilities. Customers should evaluate whether EchoScan fits their own retention and compliance requirements.

Requests and choices

People and customers can contact EchoScan about access, correction, deletion, or explanations concerning related information. The available response depends on applicable law, the relationship involved, the data category, and current processes. Identity, Workspace authority, or the customer relationship may need to be verified. An end user of a customer site should usually contact the customer that collected the business information first.

Send privacy and security requests to security@echoscan.org. General questions can be sent to contact@echoscan.org.

Policy updates

EchoScan updates this policy when the product, processing activity, or legal requirements change and revises the date at the top of the page. Material changes will be described through an appropriate site or Console notice. Customers should review this page periodically and describe their EchoScan integration accurately in their own privacy notices.