Skip to main content
AI Writing Automation for Mac | Echoo
Transparency

Echoo for Enterprise Is Here

2026-07-277 min readBy Mike
PrivacySecurityDataEnterpriseCompliance

Somebody on your team pasted a customer email into an AI chat app this morning. ChatGPT, Claude, Gemini - it does not matter which. Not to do anything clever with it, just to fix two commas and make one sentence sound less blunt before hitting send.

That is the whole story, and that is the problem. The most common way company data leaves a company in 2026 is not a breach. It is proofreading.

The two-minute habit nobody logged

Watch how the work actually happens. A support lead has a reply half-written and it reads harsh. A salesperson has a follow-up with a customer name, a contract number, and a discount they are not supposed to put in writing that way. A product manager has a paragraph of user feedback with an email address still in it.

Each one does the same thing: select, copy, switch to a browser tab, paste, type "fix the grammar and make this friendlier", copy the result back, send.

Nobody involved thinks of this as a data transfer. They think of it as a spellcheck. It takes two minutes and it happens dozens of times a day across a company, in every language your team writes in. It is the single most useful thing a language model does for most employees, and it is completely invisible to whoever is responsible for where your customer data lives.

Where that paste actually lands

When text goes into a consumer chat app, two things happen to it that do not happen to a spellcheck.

It is stored in an account history. The paste becomes a conversation, and that conversation sits in someone's personal account until they delete it. If the employee leaves, the conversation does not. If the account is a personal Gmail login rather than a company identity, you have no way to reach it at all.

On consumer tiers, it may be used to improve the vendor's models. This one needs care, because the internet states it far more confidently than the policies do. The accurate version:

  • Consumer chat tiers may use conversation content to train and improve models. This is not a ChatGPT problem - OpenAI, Anthropic, and Google all run consumer chat products, and all three have moved their consumer defaults at least once.
  • Business tiers are different. ChatGPT Team, Enterprise, and Edu do not train on business data by default, and Anthropic and Google draw the same line for their business and enterprise products. If your company pays for one of those, this specific risk is already handled for whoever is signed into the company account.
  • Individual users can change this in their data controls, and many have. Many more have never opened that settings page.

So the honest framing is not that one of these vendors is stealing your data. It is that you have no idea which of your employees are on which tier, with which settings, in which account - and neither do they. The risk is not the vendor. The risk is that the exposure is unmanaged.

Why the memo does not work

The standard response is a policy: do not put company data into AI tools.

It does not hold, for a reason that has nothing to do with discipline. The employee has a real problem - the sentence is bad and it goes to a customer in five minutes. The policy removes the tool but leaves the problem. So the paste moves to a personal phone, a personal account, and a personal browser, where you cannot see it, cannot audit it, and cannot revoke it.

You have not reduced the exposure. You have moved it somewhere with no logging.

The only version of this that works is giving people a path that is faster than the one you are trying to replace. If the compliant option takes longer than opening a browser tab, it loses.

Same models. Different door.

Here is the part that gets missed in most of these conversations: the problem is not the model. GPT, Claude, and Gemini are not a data risk because of what they are. The consumer chat app in front of them is a data risk because of what it does with the transcript.

The same models are available through the providers' APIs, and API traffic runs under different terms.

Same models, different door: pasting into a consumer chat app leaves your text in that account history, while the identical model reached through the provider API runs under no-training terms

What the API door actually changes

Three concrete differences, stated as the providers state them:

1. No training by default. OpenAI and Anthropic do not use API inputs and outputs to train their models by default. This is their published API policy, not a promise Echoo can make on their behalf - and it is the right thing to verify yourself against whatever agreement your company signs.

2. One important exception: the Gemini free tier. Google's free Gemini API tier may use the content you send to improve its products and train its models. The paid tier does not. There is no middle setting; adding billing moves the whole project to paid terms. If customer data is in scope, do not put your team on a free Gemini key. We wrote up that distinction in detail in the guide to getting a Gemini API key (opens in new tab).

3. No conversation history to inherit. An API call is a request and a response. There is no thread accumulating in a personal account, nothing to forget to delete, nothing that outlives the employee.

The model weights are identical. Your team gets the same quality of proofreading either way. The only thing that changes is which door the text goes through.

What this looks like on a Mac

That is the argument. Echoo (opens in new tab) is the shortcut layer that makes it the faster option instead of the slower one.

Text stays where it is. Your team selects a sentence in Mail, Slack, Notion, Jira, a browser textarea - anywhere - and presses a shortcut. ⌥R rewrites in place. ⌥E turns a draft written in someone's native language into natural English. Translate, summarize, and any custom command your team defines get their own shortcut.

No browser tab. No copy out, no paste back. The text never becomes a conversation in a chat app, because it never leaves the field it was written in.

Two ways to run it:

For anything that must not leave the building at all, Echoo also runs against local models through Ollama (opens in new tab), so the text never touches a network. That is the right setting for a subset of your data, and it is worth deciding which subset.

What Echoo itself can see

Fair question, and the answer differs by mode. We would rather say it plainly than let you find out later.

In Free and BYOK mode, Echoo is not in the path. The request goes from the Mac straight to the provider you configured. We do not relay it, store it, or see it. Your API keys live in the Apple Keychain on the device and are never transmitted to us.

In Managed Pro and Max plans, that is different. Echoo routes the request through its own provider account in order to fulfill the command. If your requirement is that no third party is ever in the path, BYOK is the mode you want. The Privacy Policy (opens in new tab) spells out exactly how each mode works, and Your Data, Your Control (opens in new tab) lists the complete set of usage events we collect.

To be equally plain about what does not exist yet: Echoo has no SSO, no admin console, no per-seat management, and no SOC 2 report. If those are hard requirements for your procurement process, we are not there, and we would rather tell you now than in week three of a pilot.

A short checklist before you roll this out

  • Find out what is actually happening. Ask the team, without consequences attached, where they currently paste text. You will learn more in ten minutes than from any policy audit.
  • Pick BYOK or Managed deliberately. If your compliance position is that no third party sits in the path, BYOK against a company-owned provider account is the only correct answer.
  • Read your provider tier's data terms and keep a copy. Do not rely on a blog post - this one included. Get the clause that says what happens to API inputs, and file it.
  • Never put customer data through a free Gemini key. Enable billing or use a different provider.
  • Decide what stays local. Some categories of text should not leave the machine at all. Route those through Ollama and say so in writing.
  • Set sensible defaults centrally. Assign the model per command once, so nobody is choosing a provider mid-sentence.

Talk to us about a pilot

If you want to try this with a team rather than one laptop, email [sales@echoo.ai](mailto:sales@echoo.ai). Tell us roughly how many people, which provider your company already has an account with, and what your compliance constraints look like. We will tell you honestly whether Echoo fits or whether you need something we do not have yet.

Want to try it on your own machine first? Download Echoo (opens in new tab) and run it against your own key.

Mike

Mike

Creator of Echoo

Continue Reading