Privacy Policy
How ProductEcho Cloud Service (Brand: ProductEcho) collects, protects, isolates, and processes data for developers, businesses, and autonomous AI agent runtimes.
Encrypted Secrets
Database credentials and API keys injected via MCP are encrypted at rest using AES-256 and never logged.
Isolated Workspaces
Every application container and managed database runs inside an isolated micro-VM environment.
Payment Gateway Security
PCI-DSS Level 1 compliant processing. We never store raw card numbers, CVVs, or bank credentials.
No Model Training
We do not sell your code, logs, or agent prompts to third parties, nor use them to train artificial intelligence models.
1.Introduction, Brand Identity & Scope
ProductEcho Cloud Service (Brand: ProductEcho, "we", "us", or "our") is committed to respecting your privacy and protecting the security of code, databases, financial transactions, and autonomous AI agent workflows deployed through our cloud infrastructure.
This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information and technical data when you visit our website at productecho.com, access the web console at app.productecho.com, use our Model Context Protocol (MCP) server, or subscribe to and deploy workloads on the ProductEcho Cloud Service.
2. Information We Collect
We collect information across several categories to provide, bill, and maintain our cloud infrastructure and AI runtime service:
Account & Developer Profile Data
When you sign up via email OTP, Google Sign-In, or link a GitHub/Claude account, we store basic profile details including your name, email address, Google account subject ID (when applicable), OAuth tokens, and subscription preferences. Google Sign-In only requests openid, email, and profile scopes; we use that data solely to authenticate you and create or access your ProductEcho Cloud Service workspace.
Billing & Payment Gateway Information
When you purchase a subscription plan (such as the Pro tier) or add compute credits, your payments are collected and processed securely through authorized, PCI-DSS Level 1 compliant payment gateways. ProductEcho does NOT store or process raw credit/debit card numbers, CVV codes, or banking passwords. We only store non-sensitive reference tokens, the card brand, the last 4 digits of the card, expiration month/year, billing contact details, and gateway transaction identifiers required for invoicing, account status, tax compliance, and refund issuance.
Agent Telemetry & Tool Calls
When an AI agent (such as Claude, Cursor, or ChatGPT) invokes ProductEcho MCP tools (e.g., mcp__product_echo__deploy_app), we log execution requests, tool status codes, and container build logs necessary to present deployment output and runtime diagnostics to you.
Infrastructure Metrics & Usage
We automatically aggregate hardware usage metrics (CPU, RAM, DB storage volume, HTTP requests, bandwidth) to manage cloud resources, calculate metered usage, and prevent platform abuse.
3. How We Use Your Information
ProductEcho Cloud Service uses collected information strictly for operational, billing, and security purposes:
- Provisioning, maintaining, and scaling isolated PostgreSQL databases, container microservices, and AI agent runtimes.
- Executing programmatic MCP tool instructions issued from authorized AI assistant sessions.
- Processing subscription billing, recurring renewals, and refunds through certified payment gateways, and delivering electronic receipts and tax invoices.
- Issuing and renewing TLS/SSL certificates for public HTTPS URLs (
*.productecho.com). - Detecting and blocking malicious runtime execution, crypto-mining, denial-of-service attempts, or payment fraud.
- Providing customer support, billing resolution, and technical troubleshooting.
4.Payment Gateway Compliance & Financial Security
When you initiate a paid subscription or add-on purchase for the ProductEcho Cloud Service, financial transactions are handled with industry-standard payment security:
PCI-DSS Level 1 Certification: All credit card, debit card, UPI, net banking, and electronic payment transactions are processed through certified PCI-DSS Level 1 compliant payment gateways. The gateway is solely responsible for handling and storing cardholder data.
End-to-End Encryption: All checkout sessions and payment authorization transmissions are secured over 256-bit Transport Layer Security (TLS/SSL).
Zero Raw Card Storage: ProductEcho never sees, stores, or logs raw credit card numbers, CVVs, or cardholder banking passwords on our servers. We use secure cryptographic tokens issued by our payment gateway partners to manage recurring renewals and cancellations.
Tax Invoicing & Records: We maintain payment reference numbers, amounts, timestamps, and customer tax identifiers as required by applicable tax authorities and accounting standards.
5.Infrastructure & Secret Isolation
Security is foundational to ProductEcho Cloud Service runtime architecture. All customer workloads operate in sandboxed containers with strict network isolation and non-root execution.
Connection strings, database passwords, and environment secrets injected during MCP tool calls are encrypted using AES-256 before storage and injected directly into ephemeral runtime memory.
6.Third-Party Service Providers & Integrations
ProductEcho integrates with trusted third-party partners to deliver our cloud platform:
- Payment Gateways: PCI-DSS certified payment processors for subscription billing, recurring payments, invoicing, and refund disbursements.
- AI Ecosystem Providers: Anthropic (Claude), OpenAI (ChatGPT), Cursor, and GitHub. When configuring MCP servers, data exchanged with these providers is governed by your agreements with them.
- Cloud Infrastructure Providers: Tier-4 data centers and Kubernetes cloud providers hosting our container runtimes and managed PostgreSQL clusters.
7.Your Data Privacy Rights (GDPR & CCPA)
Under GDPR, CCPA, and applicable global data protection regulations, you possess rights to access, correct, export, or permanently erase your personal data and deployed infrastructure assets. You may delete your databases, apps, or entire workspace account at any time directly through the ProductEcho dashboard or by submitting a written data request to our legal and privacy team.
8.Privacy & Legal Contact
If you have questions regarding this Privacy Policy, wish to exercise your data privacy rights, or need clarification regarding payment gateway data processing, please contact our team:
Turnaround SLA: Inquiries acknowledged and addressed within 24–48 business hours.