Legal
Last updated: June 2026
CalmEcho ("we", "us", "our") operates the CalmEcho meditation and wellness application available at thecalmecho.com and associated mobile and web applications. We act as the data controller for the personal data described in this policy.
For privacy enquiries, contact us at our contact page or email: privacy@thecalmecho.com
We collect the following categories of personal data:
Mood entries and wellness session data may constitute health-related personal data (a special category under GDPR Art. 9). See Section 4 for the additional lawful basis we rely on for processing this data.
Consent — Art. 6(1)(a)
You give explicit consent when you create an account by accepting these terms. You may withdraw consent at any time by deleting your account.
Contract — Art. 6(1)(b)
Processing is necessary to fulfil the subscription contract when you purchase Premium access.
Legal Obligation — Art. 6(1)(c)
We retain payment records to comply with tax and accounting laws.
Legitimate Interests — Art. 6(1)(f)
Security monitoring, fraud prevention, and service improvement.
Mood entries and wellness session data constitute special category personal data (health information) under GDPR Art. 9. We process this data on the basis of your explicit consent under Art. 9(2)(a), given when you tick the consent checkbox at registration. You may withdraw this consent at any time by deleting your account; your data will be purged within 30 days.
We share data only with the following processors, each bound by data processing agreements:
Supabase
Authentication and database hosting · EU (AWS Frankfurt)
Stripe
Payment processing and subscription billing · USA (Standard Contractual Clauses apply)
Resend
Transactional email delivery · USA (Standard Contractual Clauses apply)
OAuth sign-in (if used) · Global
We do not sell your data to any third party.
If you are in the European Economic Area or United Kingdom, you have the following rights:
Right of Access (Art. 15)
Request a copy of all data we hold about you.
Right to Rectification (Art. 16)
Correct inaccurate or incomplete data.
Right to Erasure (Art. 17)
Request deletion of your data ("right to be forgotten").
Right to Portability (Art. 20)
Receive your data in a machine-readable format.
Right to Restriction (Art. 18)
Limit how we process your data.
Right to Object (Art. 21)
Object to processing based on legitimate interests.
To exercise any right, contact us via our contact page. We will respond within 30 days. You also have the right to lodge a complaint with your local data protection authority.
We use strictly necessary storage only:
Because we use only strictly necessary storage, no cookie banner is required under GDPR Recital 30. You can clear this data at any time by signing out or clearing your browser storage.
Do Not Track: Some browsers transmit "Do Not Track" (DNT) signals. We do not currently alter our data practices in response to DNT signals, as no industry-wide standard for responding to them has been adopted. California residents may exercise opt-out rights under Section 12 instead.
Stripe and Resend are US-based companies. Data transferred to them is protected under the EU Standard Contractual Clauses (SCCs) approved by the European Commission, which provide equivalent data protection safeguards. Supabase stores your database on AWS infrastructure in the EU (Frankfurt) by default.
CalmEcho is not intended for users under 18 years of age. We do not knowingly collect personal data from children. If you believe a child has provided us with personal information, please contact us and we will delete it promptly.
We implement appropriate technical and organisational measures to protect your data: row-level security (RLS) on all database tables, encrypted connections (HTTPS/TLS), server-side JWT verification for all authenticated API calls, and service-role database access restricted to the backend only.
In the event of a personal data breach likely to result in a high risk to your rights and freedoms, we will notify affected users without undue delay and report to the relevant supervisory authority within 72 hours of becoming aware of the breach, as required by GDPR Art. 33–34.
If you are a California resident, the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA) grants you the following rights in addition to those above:
Right to Know
Request disclosure of the categories and specific pieces of personal information we have collected about you in the past 12 months.
Right to Delete
Request deletion of personal information we have collected, subject to certain exceptions.
Right to Correct
Request correction of inaccurate personal information we maintain about you.
Right to Opt-Out of Sale
We do not sell or share your personal information for cross-context behavioural advertising. No opt-out action is required.
Right to Limit Sensitive Data Use
We do not use sensitive personal information (wellness data, mood entries) for purposes beyond delivering the Service.
Right to Non-Discrimination
We will not discriminate against you for exercising any CCPA right — no price changes, service denial, or reduced quality.
CalmEcho does not sell and does not share your personal information with third parties for cross-context behavioural advertising purposes. No opt-out link is required, but we include this confirmation for transparency.
To exercise any California right, contact us via our contact page or email privacy@thecalmecho.com. We will respond within 45 days (with a possible 45-day extension where reasonably necessary). We will not require you to create an account to submit a request.
Residents of Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA), Texas (TDPSA), and other states with comprehensive privacy laws have similar rights to access, correct, delete, and port their data, and to opt out of sale and targeted advertising. The same contact process applies. We will respond within the timeframe required by your state's law.
If CalmEcho is involved in a merger, acquisition, asset sale, bankruptcy, or reorganisation, your personal data may be transferred to the acquiring entity as part of that transaction. We will notify you by email or prominent in-app notice at least 30 days before your data is transferred and becomes subject to a different privacy policy. The successor entity will be required to honour all commitments made in this policy or obtain fresh consent from you.
We may update this policy from time to time. We will notify you by email at least 30 days before any material change takes effect. The "Last updated" date at the top of this page reflects the most recent revision.
Questions? Contact us or view our Terms of Service.