Privacy Policy
How ProductEcho collects, protects, isolates, and processes data for developers and autonomous AI agent runtimes.
Encrypted Env Secrets
Database credentials and API keys injected via MCP are encrypted at rest using AES-256 and never logged.
Isolated Workspaces
Every app container runs inside an isolated micro-VM.
No Model Training
We do not sell your code, logs, or agent prompts to third parties, nor use them to train AI models.
1. Introduction & Overview
ProductEcho Platform Inc. ("ProductEcho", "we", "us", or "our") is committed to respecting your privacy and protecting the security of code, databases, and autonomous AI agent workflows deployed through our services.
This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website at productecho.com, use our Model Context Protocol (MCP) server, or deploy applications using our automated cloud infrastructure.
2. Information We Collect
We collect information in three main categories to provide and maintain our AI runtime service:
Account & Developer Profile Data
When you sign up or link a GitHub/Claude account, we store basic profile details including your name, email address, OAuth tokens, and subscription preferences.
Agent Telemetry & Tool Calls
When an AI agent (such as Claude or Cursor) invokes ProductEcho MCP tools (e.g., mcp__product_echo__deploy_app), we log execution requests, tool status codes, and container build logs necessary to present deployment output to you.
Infrastructure Metrics & Usage
We automatically aggregate hardware usage metrics (CPU, RAM, DB storage volume, HTTP requests, bandwidth) to manage cloud resources and prevent abuse.
3. How We Use Your Information
ProductEcho uses collected data strictly for operational and security purposes:
- Provisioning, maintaining, and scaling isolated PostgreSQL databases and Web microservices.
- Executing programmatic MCP tool instructions issued from authorized AI assistant sessions.
- Issuing and renewing TLS/SSL certificates for public HTTPS URLs (
*.productecho.com). - Detecting and blocking malicious runtime execution, crypto-mining, or network abuse.
- Providing customer support and technical troubleshooting.
4. Infrastructure & Secret Isolation
Security is foundational to ProductEcho runtime design. All customer applications operate in sandboxed containers with strict network isolation.
Connection strings, database passwords, and environment secrets injected during MCP tool calls are encrypted using AES-256 before storage and are injected directly into ephemeral runtime processes.
5. Third-Party Integrations
ProductEcho integrates with AI ecosystem providers including Anthropic (Claude), OpenAI (ChatGPT), Cursor, and GitHub. When configuring MCP servers, data passed to these providers is subject to their respective privacy policies and terms of service.
6. Your Data Privacy Rights (GDPR & CCPA)
Under GDPR and CCPA, users have the right to request access to, correction of, or permanent deletion of their personal information and deployed infrastructure data. You may delete your databases or account at any time directly through the ProductEcho dashboard or by contacting our Data Protection Officer.
7. Privacy Contact & Questions
If you have questions regarding this Privacy Policy or wish to exercise your privacy rights, please reach out to our privacy team: