Effective from October 3, 2026 · echo-assistants.tech
This page explains, point by point, what data the Echo project processes, why, who it is shared with, how long it is kept and how to delete it. We collect what the features need in order to work, and we do not sell data.
Echo is a Discord bot and dashboard at echo-assistants.tech, together with related services: server monitoring (monitoring.echo-assistants.tech), server stores, the Echo Deal escrow service (deal.echo-assistants.tech), a Minecraft server with its own website and launcher (minecraft.echo-assistants.tech), the Mafia and Bunker games, and our Discord server Echo Studio.
This policy applies to everyone who uses the bot on their server, signs in on the website, plays on our Minecraft server, takes part in escrow deals or simply interacts with Echo features (submits a form, votes, writes in a ticket).
By using the service, you agree to the data processing described here. If you do not agree, do not add the bot, do not sign in on the website and do not play on the server.
The bot receives from Discord only what it is permitted to: IDs and names of users, servers, channels and roles, server nicknames, and message text. We use this only for features that the server’s administration has enabled.
Sign-in uses Discord’s official OAuth2. We request your profile (identify), your email address (email) and the list of your servers (guilds); adding you to our server (guilds.join) is requested only if you chose auto-join yourself. The server list (name, icon, whether you are the owner) is saved for the dashboard.
We save the email address from Discord and its “verified” flag each time you sign in. We use a verified email to show your albums from the fotora.ru image host (the address is shared with fotora for this) and for account service emails: the deletion confirmation code, “your data is ready” and reminders about a scheduled deletion, and notifications about replies to your support requests. We send no marketing emails. Your email is deleted together with your account.
We have no access to your Discord password. The session is stored in an encrypted cookie (AES-256-GCM) in your browser; it contains a Discord access token used to check your permissions.
If two-factor protection is enabled, we send a one-time code to Telegram. The code is valid for 5 minutes, the number and frequency of attempts are limited, and the code is deleted after use or when it expires.
Emails sent to @echo-assistants.tech addresses (echo@, garant@ and others) are received by our own mail server. We store the sender's address and name, the subject, text, attachments and the result of the sender check (SPF, DKIM, DMARC and the IP address of the sending mail server) so that we can read the email and reply. Only the project's leadership can see these emails.
To protect your account from takeover, we record sign-ins to the site and the Minecraft dashboard (IP address, browser and operating system) and signs of compromise: reuse of a cookie after sign-out, guessing of the two-factor code, guessing of Minecraft passwords. When we see such signs, we end all sessions of the account or disable it until you contact support. Decisions and their grounds are visible only to the project leadership.
We use only necessary cookies. There are no advertising or tracking cookies, and no third-party analytics. Our own page-view counter records only the page address and the day — no IP and no cookies.
The balance is topped up via YooMoney and Crypto Pay (@CryptoBot in Telegram). Card and wallet details are entered on the payment service’s side and never reach us.
Some features run on Anthropic’s Claude models. They receive only the text needed for a reply — without your IDs, email or payment data.
We do not sell data, do not show ads and do not use tracking services. Data goes only to those without whom a feature cannot work:
Data is stored on a rented server in the Netherlands.
The services are intended for people who have reached the minimum age for using Discord in their country. We do not knowingly collect data from children below that age.
We update the policy when the service changes. The current version is always on this page, with the date at the top; we announce significant changes in the news.