ECHO Steam Privacy Policy
For the ECHO desktop application distributed under Steam App ID 5105090.
Effective: 2026-08-15 · Last updated: 2026-08-15
阅读中文版 · View the ECHO Next Privacy Policy
This Policy applies only to the ECHO edition distributed through Steam ("ECHO Steam"). It is separate from the ECHO End User License Agreement, third-party notices, and source-available license.
1. Overview
ECHO Steam is a desktop music player built around a local music library. Basic local playback does not depend on official ECHO servers. ECHO does not sell or rent user data, include an advertising-tracking SDK, automatically upload diagnostic reports, or upload your complete local library, per-play history, original audio files, lyrics, artwork, file paths, audio-device list, or remote-library credentials to official ECHO servers.
When you choose to use Steamworks, remote libraries, online lyrics or metadata, OPRA, Discord Rich Presence, Last.fm, or another network feature, the data required for that feature is sent to the relevant third party or server configured by you. Those services process data under their own terms and privacy policies.
2. Data Processed and Stored Locally
ECHO Steam may process and store on your device:
- selected music folders, paths, file names, audio tags, formats, duration, artwork, and lyrics;
- the library index, queue, playlists, likes, playback history, and locally derived listening summaries;
- theme, language, audio output, device, EQ, DSP, lyrics, shortcut, and other app settings;
- server addresses, account identifiers, access tokens, passwords, and other connection settings for remote libraries;
- Workshop item IDs, versions, integrity digests, install, enable, and applied state;
- caches, backups, logs, crash-recovery information, and diagnostic reports.
This data is normally stored in the ECHO Steam app-data directory for the current operating-system user or in a cache, backup, or mount location you explicitly select. Removing ECHO databases, caches, or settings does not remove original music files unless you separately delete those files through the file system.
3. Steamworks Data
ECHO Steam uses Steamworks through the local Steam client. ECHO does not request or store your Steam password, Steam Guard code, or Steam session cookies. Account identifiers, ownership state, and authentication data required by Steamworks stay within the supported local Steam path; they are not exposed to Workshop themes or written to ordinary user-facing diagnostic reports.
Valve's handling of Steam account and service data is governed by the Valve Privacy Policy.
Steam Cloud
When Steam Cloud is available for the App and you have not disabled Cloud in Steam, ECHO uses Steam Remote Storage
to synchronize one versioned file named echo-steam-settings-v1.json. It contains only an allowlisted
projection of portable app settings plus version, update time, and an integrity digest.
The projection excludes the library database, music files, playlist contents, per-play history, absolute paths, window position, audio-device or hardware identifiers, proxy and remote-service configuration, passwords, tokens, cookies, authorization or session data, Steam entitlement state, logs, and diagnostic reports. ECHO compares local and cloud settings at startup, schedules a delayed update after settings change, and also provides manual upload and download actions.
You can disable Steam Cloud globally or for ECHO in Steam. Disabling synchronization stops future transfers but does not automatically delete a file already stored by Valve.
Steam Rich Presence
Steam Rich Presence is enabled by default. The default Music preset submits the current title, artist, album, and playback progress rounded to 15-second intervals to the local Steam client. Genre, playback order, BPM, quality, format, and bit-perfect state are off by default and are included only if you enable their individual options.
This information may be shown to Steam friends according to your Steam privacy and friends settings. You can select the Minimal or Privacy preset, disable individual fields, or turn Rich Presence off. Turning it off clears the current ECHO Rich Presence fields immediately.
Achievements, Optional Steam Stats, and Leaderboards
ECHO may submit fixed achievement identifiers and unlock or progress state derived from local playback facts.
Steam Listening Stats is off by default and requires a separate confirmation. If enabled and available, ECHO submits only eight integer aggregates associated with the active Steam account: listening minutes, qualified completed plays, unique tracks completed, longest listening streak, night listening minutes, longest listening session, rediscovered tracks, and completed albums. Titles, artists, albums, lyrics, artwork, paths, devices, timestamps, and individual playback rows are excluded.
Steam Leaderboards is off by default and requires a separate confirmation. If enabled, ECHO may submit five fixed best integer scores and seven fixed-order integer summaries for listening time, completed tracks, longest streak, longest session, and rediscovered-track leaderboards. Read results may include a public persona name supplied by Valve, rank, and score.
Disabling stats or leaderboards stops future reads and submissions but does not automatically delete values or scores already stored by Valve. Removing local playback history does not lower a previously submitted best value.
Steam Workshop
When you browse, subscribe to, unsubscribe from, or download Workshop content, Steam processes your Steam account, item IDs, subscription relationship, download state, and related requests. ECHO reads item metadata, install location, and state locally and stores item ID, version, integrity digest, enable, and applied state to validate, isolate, repair, and explicitly apply content.
ECHO does not upload your local music files, file paths, full playback history, or remote-service credentials to the Workshop. A custom UI theme that you explicitly enable may process sanitized library, playback, queue, or spectrum data inside an isolated iframe according to its declared capabilities. The frame has no external network, Node, file-system, or Steamworks access, so that data does not leave the device through the theme. Enable only Workshop content you trust.
4. Remote Libraries and User-Configured Services
ECHO Steam supports WebDAV, Jellyfin, Emby, Subsonic/Navidrome-compatible services, and SMB or SSHFS locations mounted through the operating system when explicitly configured by you.
For a network remote library, ECHO connects directly to the server you enter. To authenticate, browse, index, load artwork or lyrics, and stream audio, that server may receive its address, username, password or token, folder and media IDs, search or pagination parameters, media metadata, byte-range requests, IP address, and ordinary HTTPS request metadata. Official ECHO servers do not proxy these connections. The server operator is responsible for data it receives; review its policy and connect only to servers you trust.
SMB and SSHFS are currently accessed through a path that you explicitly select or mount in the operating system. Authentication for those mounts is normally handled by the operating system or mount tool.
5. Other Optional Network Features
- Online lyrics or metadata candidates: title, artist, album, duration, or search text is sent to the relevant provider.
- OPRA headphone correction: public headphone model, correction-curve, and attribution resources are fetched; the local library, playback history, and device list are not sent.
- Discord Rich Presence: when enabled, playback state and track display information are submitted to the local Discord client.
- Last.fm: only after you connect and enable it, account authorization plus title, artist, album, duration, and play time needed for Now Playing or Scrobble is sent to Last.fm.
- Direct radio streams, local-network devices, or other user-owned services: connection and playback data is sent to the address you select.
These services may receive your IP address and ordinary network-request metadata. Their own policies determine how they process and retain data.
6. Diagnostics, Feedback, and Support
Logs, crash-recovery information, and diagnostic reports are stored locally by default. ECHO does not automatically upload them to the maintainer or to a third-party crash-analytics service. A recipient receives diagnostic content only when you choose to export, copy, upload, or send it.
Reports may contain the ECHO version, operating system, errors and feature state, hardware or audio state, and sanitized file-name or path summaries. Review a report before sharing and remove anything you do not want to disclose.
7. Sharing, Retention, and Deletion
ECHO does not sell or rent personal data or build an advertising profile from your local library. Data leaves the device only when you use a network feature described in this Policy, choose to send feedback, diagnostics, or support material, or processing is required by law.
Local data is retained until you clear it in the app, remove app data through the uninstaller, or delete the relevant directory. Third parties retain data under their own policies. Steam Cloud, stats, leaderboards, achievements, Workshop subscriptions, and Steam account data are managed by Valve; turning a feature off in ECHO may not delete historical data stored by Valve.
8. Your Choices and Rights
- Avoid importing music folders or remove scanned folders.
- Clear local caches, playback history, settings, backups, and other app data.
- Disable Steam Cloud, Rich Presence, Steam Stats, leaderboards, Discord Rich Presence, Last.fm, and other optional network features.
- Disconnect a remote library and remove its local connection settings.
- Review diagnostics or feedback before sending them.
- Contact the ECHO maintainer to ask about data actually held by ECHO or to exercise applicable access, correction, deletion, restriction, or objection rights.
For data independently controlled by Valve or another third party, use that service's privacy tools or contact the service directly.
9. Children's Privacy
ECHO Steam is intended for general desktop users and is not directed to children. The ECHO maintainer does not knowingly collect children's personal information through ECHO Steam.
10. Policy Changes
If ECHO Steam's data handling changes materially, this Policy will be updated with a new “Last updated” date and relevant details. Additional notice will be provided where appropriate.
11. Contact
ECHO is maintained by Moekotori. For privacy questions or requests, email nyafairy233@gmail.com.