Cookies are small text files a website stores in your browser. Here's exactly what Echo uses them for — no more, no less.
Essential cookies (the only kind we currently use)
When you sign in, Echo sets a couple of small cookies through Auth.js, our sign-in library, to keep you logged in and to protect the sign-in form from cross-site attacks:
- A session cookie — remembers that you're signed in, so you don't have to log in again on every page.
- A CSRF-protection cookie — a security measure used while you're submitting the sign-in form.
These are strictly necessary — Echo can't keep you signed in without them, so there's no cookie banner or opt-out for these specifically. If you don't want them, don't sign in (you can still browse the public parts of the site).
What we don't use
Echo doesn't currently run any analytics, advertising, or third-party tracking cookies — no Google Analytics, no ad pixels, nothing that follows you around the web. If that changes, we'll update this page first and add a proper cookie consent banner before it happens, not after.
Managing cookies
You can block or delete cookies through your browser's settings. Since our only cookies are the sign-in ones above, blocking them just means you won't be able to stay signed in.
Changes to this policy
We'll update the “last updated” date above if what we use changes, and post the updated version here.
Contact us
Questions about this policy? Email support@myecho.com.au.