A note from us

    Trust & Automation

    A short, honest walkthrough of how your campaign data is handled — what we do with it, who else sees it, and what we don't do with it.

    These are the questions we'd want answered before trusting any tool with our campaign notes. So instead of hiding the answers in legalese, we've written them out the way we'd explain them to a friend at the table. The formal policy still exists at the bottom of this page — but the plain version is right here.

    Which automation tools does Epic's Echo use?

    Two kinds, in two very different places.

    The text work — turning your recording into a recap, picking out the NPCs your party met, suggesting the next session's hooks — goes through OpenAI's API. We pick smaller, more efficient models for most of the work, and only reach for the larger ones when the task genuinely needs them.

    The voice work — transcribing your recordings, and narrating recaps aloud — runs on speech models that we host ourselves on dedicated GPUs. Your table's audio doesn't get passed around to multiple vendors.

    Where does my data actually live?

    Its permanent home is our own infrastructure, end to end. We run on DigitalOcean:

    — Your audio files sit in our private storage bucket while we process them — and the raw recording is deleted the moment your recap is done, unless your campaign asked us to hold it 14 days.
    — Your transcripts, recaps, campaigns, characters, hooks and notes live in our managed PostgreSQL database.
    — Nothing about your campaign is mirrored to third-party cloud services or training datasets. What sits outside, and only temporarily, is what the training question below describes: the model provider's short-term copy kept for abuse investigation, and a background job waiting to be collected.

    That database is the only permanent home for any of it — the audio is just the temporary raw material.

    Do the model providers train their models on my campaign?

    We don't — and on their published terms, they don't either. The difference between those two halves is worth spelling out.

    OpenAI's API terms are explicit: data sent through their API is not used to train or improve their models. Two things do sit on their side, though, and they're worth separating. One is a short-term copy — up to 30 days — kept so they can investigate abuse complaints, held longer only where the law requires it. The other is the job itself: longer sessions go out as a background request, which means the request and its result sit on their side long enough for us to fetch the result by id. How long that copy lives is their policy, not ours. Both rest on their published policy rather than a contract we hold: we have not signed our own agreement covering it, so we name whose promise it is instead of printing it as ours.

    The voice models we run ourselves never leave our infrastructure at all, so there's no third-party brain to train.

    Who else sees my data?

    Nobody, in the “sold or shared” sense. We don't sell data, we don't hand it to advertisers, and we don't share it with other tabletop products.

    The only services that touch any of it are the ones that have to, and each only sees the slice they need:

    OpenAI sees text when it processes a request; the longer jobs we submit in the background also sit on its side until we collect the result.
    — Our self-hosted speech models run on Modal's GPU infrastructure, but the models and the data are ours.
    Stripe, if you subscribe, sees your email and payment details — never a word of your campaign content.
    Resend sends our transactional emails (recap-ready notifications and the like).
    PostHog records anonymous product analytics — which buttons get clicked, not what's inside your sessions.

    So does it really only stay on your servers?

    The stored copy, yes. Your campaign only has one permanent home, and that's with us.

    Most requests to the model providers above are processed in flight — text goes out, the result comes back, and we save the result. The longer jobs are the exception: we submit them as background requests, so the request and its result sit on the provider's side until we collect them. Either way the permanent copy is ours, and (per the question above) they don't train on it.

    Can I delete my data?

    Yes. You can delete individual sessions from inside the app at any time, and they're removed from our database and storage bucket.

    We also clean up after ourselves automatically: the raw audio recording is deleted the moment a session's recap is done — or after 14 days, if that campaign asked us to hold it. Once we've turned it into your transcript, recap and wiki, the original recording has done its job — so we don't keep it around.

    If you'd like your entire account wiped — every session, every transcript, every note — drop us a message through the contact page and we'll handle it personally. We don't have a self-serve “delete account” button yet, and we'd rather tell you that than pretend we do.

    What about energy use and the environment?

    Here we want to be straight with you rather than wave a green flag we haven't earned. We don't have a formal sustainability policy written up yet.

    What we do in practice: we route the lightweight tasks (which is most of the work, actually) to small efficient models, and only call the larger ones when the task genuinely needs the extra horsepower. That keeps the energy-per-session meaningfully lower than if we just used the biggest model for everything.

    Our hosting provider publishes its own datacenter sustainability commitments, and the model providers we use each have theirs. It's a fair question to push us on — and it's something we'd like to write up properly soon.

    If any of this raises more questions, just reach out — we'd much rather answer them than leave you guessing.

    Send us a question →

    — The Epic's Echo team

    Third-party licenses

    Starfinder 2e rules content in Epic's Echo is used under the ORC License: paizo.com/orclicense

    This product is licensed under the ORC License located at the Library of Congress at TX 9-307-067 and available online at various locations including paizo.com/orclicense, azoralaw.com/orclicense, and others. All warranties are disclaimed as set forth therein. This product is based on the following Licensed Material: Starfinder Player Core © 2025 Paizo Inc., Authors: Jessica Catalan, Thurston Hillman, Jenny Jarzabski, Mike Kimmel, and Dustin Knight Starfinder GM Core © 2025 Paizo Inc., Authors: Jessica Catalan, Thurston Hillman, Jenny Jarzabski, Mike Kimmel, and Dustin Knight Starfinder Alien Core © 2025 Paizo Inc. Authors: Kate Baker, Lau Bannenberg, Rigby Bendele, Vishesh Bhartiya, Joseph Blomquist, Jeremy Blum, Tineke Bolleman, Brent Bowser, Michael Bramnik, Patrick Brennan, Charlie Brooks, Jessica Catalan, Brite Cheney, Jeremy Corff, Caryn DiMarco, Anthony Dollinger, Steve Fidler, Kim Frandsen, Andrew D. Geels, Basheer Ghouse, Sen H.H.S., Katrina Hennessy, Thurston Hillman, Joan Hong, Jenny Jarzabski, Sara Jeffers, Mikko Kallio, Lysle Kapp, Mike Kimmel, Dustin Knight, Cole Kronewitter, Mahpiya, Letterio Mammoliti, Randal Meyer, Jacob W. Michaels, Matt Morris, Dennis Muldoon, Quinn Murphy, Elizabeth V Nold, Chesley Oxendine, Emily Parks, Glen Parnell, Randy Price, Kyle T. Raes, Jessica Redekop, Erin Roberts, James Rodehaver, David N. Ross, Pidj Sorensen, Joel Southall, Kendra Leigh Speedling, Drew Taylor, Sam W Tennyson, Jalen Todd, Ruvaid Virk, Viditya Voleti, Christopher Wasko, Nicholas Wasko, Jackson Wery, Shan Wolf, and Basil Wright. Starfinder Galaxy Guide © 2025 Paizo Inc., Authors: Kate Baker, Rigby Bendele, Joseph Blomquist, Jessica Catalan, John Compton, Anthony Dollinger, Alexi Greer, Sen H.H.S., Thurston Hillman, Jenny Jarzabski, Mike Kimmel, Dustin Knight, Dennis Muldoon, Quinn Murphy, Emily Parks, Letterio Mammoliti, and Kendra Leigh Speedling Reserved Material: all EpicEcho product code, UI, prompts, database schemas, and non-mechanical content are the Reserved Material of EpicEcho and are not licensed under the ORC License.

    The formal documents are still here, for the record: the Privacy Policy and the Terms of Service.