Privacy Policy

Effective 2026-07-19. This policy describes what the Build Tracker connector collects, how it is used and stored, and how to delete it.

What we collect

How it is stored

Plan content is stored in a Cloudflare Durable Object (SQLite) at the edge. OAuth material is stored, hashed, in Cloudflare Workers KV. No third-party analytics, advertising, or tracking is used.

Public status dashboard

The browser view at /dashboard and its data endpoint /api/panel are public and unauthenticated. They expose a reduced, read-only status board — plan names, gate names and states, progress counts, the current focus directive, blockers, and skills/dependencies. They deliberately omit per-objective evidence strings, the cross-agent activity log, and agent identities; that full detail is returned only over an authenticated MCP session to the in-chat widget. Treat plan names, gate names, and focus text as publicly visible, and never place secrets or personal data in them.

How it is used

Solely to provide the service — returning your plan state to your MCP client and authenticating requests. We do not sell your data, share it with third parties, or use it to train models.

Retention & deletion

Plan data persists until deleted. You can disconnect the connector in your MCP client at any time to revoke access. To delete stored plan/OAuth data, email support@echosforge.com and it will be removed within 30 days.

Security

All traffic is HTTPS. Access requires OAuth 2.1; tokens are stored only as hashes. Tools are least-privilege and annotated (read-only vs. write); write actions are approval-gated in supporting clients.

Contact

Questions or deletion requests: support@echosforge.com.