Tellspike ("we," "our," or "us") provides an AI-powered voice companion for personal reflection and emotional well-being through the Tellspike iOS application ("the App"). This Privacy Policy explains what data we collect, how we use it, and the choices you have.
We designed Tellspike with privacy at its core. Everything that can run on your device does, and we never sell your data. Section 4.2 describes what goes to the cloud and when.
Tellspike does not collect usage analytics, crash reports, or performance telemetry. We do not implement any first-party analytics, and we do not integrate any third-party analytics or crash reporting SDK (no Firebase, Mixpanel, Amplitude, Segment, Sentry, Crashlytics, or equivalent).
If you have separately opted in to share analytics with Apple under iOS Settings → Privacy & Security → Analytics & Improvements, iOS may include Tellspike in what it sends to Apple. That is a relationship between you and Apple; Tellspike neither asks for that data nor receives it. You can disable this at any time in iOS Settings.
Tellspike prioritizes on-device AI so your conversation text stays on your phone by default. On-device processing involves no data transmission and is not disclosed in our App Store privacy nutrition label because the data never leaves the device.
Apple Foundation Models: Answers are generated on your device by the language model built into iOS. No conversation data is sent to any server.
Tellspike requires Apple Intelligence and does not run without it. On a device that cannot run it, the app explains why and stops, rather than quietly sending your conversation somewhere else.
You can attach a photo to a message, either from your photo library or by taking one with the camera. Tellspike opens the camera only when you choose to, never on its own. When you do, your device reads it using Apple’s Vision framework and produces text: any words legible in the image, and up to three labels for what is in it. Spike responds to that text.
The photo itself never leaves your device, in either mode. This is enforced by the type system rather than by policy: the stored photo type is deliberately not encodable, so it cannot be serialized into a request body at all. A test fails the build if that ever changes.
When cloud AI is needed, Tellspike routes requests to one of these named providers:
No other cloud AI providers are used without updating this policy and notifying you in the App.
You control cloud AI through Tellspike’s privacy mode. Switching to Private stops it immediately and completely:
| Mode | Cloud AI | What Happens |
|---|---|---|
| Private | OFF | All processing stays on your device. Nothing leaves your phone. No internet required. |
| Cloud | ON, with protections | Conversation text is sent to a cloud provider with personal details removed first. You must explicitly switch this on. |
Default: The App defaults to Private. You must actively switch to Cloud to enable cloud AI processing. You can switch back at any time, and cloud processing stops immediately. Under every message that went to the cloud there is a marker you can tap to read the exact text that left your device.
You can see what was sent. Every message that went to the cloud carries a marker underneath it. Tap it and it shows the exact text that was handed to the provider for that turn, taken from the string given to the network layer rather than reconstructed afterwards. A message handled on your device carries no marker, so the absence of one means nothing left.
In Cloud mode:
We want to be straight with you about the limits of what removing direct identifiers can do. In Cloud mode, we strip names, phone numbers, addresses, and similar identifying tokens from your conversation text before it leaves your phone. That protects against the most common ways a stray log line gets traced back to a real person. What it does not do is mask how you write. Academic research has shown that writing style itself can act as a fingerprint: word choices, sentence rhythms, and topic patterns can re-identify an author from text that has had all the obvious identifiers removed, given enough samples. We're not aware of any consumer AI app that defends against this, and we don't claim to either. If you're sending text to a cloud provider for any reason, treat it the way you'd treat sending a postcard: scrubbed of the name and return address, but still in your own handwriting. The free, on-device tier sidesteps this entirely because nothing leaves the phone.
Your conversations are not. Message text, Spike’s state, and your insights live on your device. They are never uploaded, in either mode. In Cloud mode the anonymized text of a single turn is sent to the provider to generate that one reply, and you can read exactly what was sent by tapping the marker under that reply.
If you have never purchased anything, we hold nothing at all. The free tier makes no network requests. This is enforced by a test that fails the build if any outbound request is made.
If you subscribe or buy credits, a billing record exists. It is keyed to the transaction identifier Apple issues for your purchase, and it holds your credit balance so that usage can be metered and refunds honored. It does not hold your name, email address, phone number, or any conversation content. Tellspike has no login: it never asks you to create an account and there is no password to set. Your App Store purchase is the credential, which also means that if a subscription lapses, this device may no longer be able to prove a billing record is yours even though the record still exists. Contact privacy@tellspike.com and we will delete it.
| Data Type | Retention | How to Delete |
|---|---|---|
| Conversations | Until you delete them | Settings > Reset Tellspike, or uninstall the App |
| Spike companion state | Until you delete | Settings > Reset Tellspike, or uninstall the App |
| Cloud provider logs | Up to 30 days (provider policy) | Deleted automatically by provider |
| Billing record (subscribers only) | While your subscription or credit balance is active | Settings > Delete billing account, which starts a 30-day grace period |
Deleting the App removes all locally stored data, including conversations, Spike companion state, and preferences.
We never sell, rent, or trade your personal information, conversation data, or usage patterns to any third party for any purpose.
| Third Party | What Is Shared | When | Your Control |
|---|---|---|---|
| Anthropic (Claude API) | Anonymized conversation text | Cloud mode only | Switch back to Private to stop |
| OpenAI (GPT API) | Anonymized conversation text | Cloud mode only | Switch back to Private to stop |
| Apple (OS-level, not via Tellspike) | Whatever iOS diagnostics you opted into at the OS level, routed entirely by Apple. Tellspike does not push anything to this pipeline. | If you opted in during iOS setup | iOS Settings > Privacy & Security > Analytics & Improvements |
| Law enforcement | As required by valid legal process | Court order, subpoena, or legal obligation | N/A |
We do not use third-party advertising networks, data brokers, or social media tracking pixels.
You have full control over how your data is processed:
California residents have the right to:
If you are in the European Economic Area, you have the right to access, rectify, erase, restrict, or port your personal data, and to lodge a complaint with a supervisory authority. Our legal basis for processing is your explicit consent (you must switch on Cloud mode yourself; Private is the default).
Tellspike is a personal wellness and reflection tool. It is not a medical device, does not provide medical advice, diagnosis, or treatment, and is not a covered entity under HIPAA. Tellspike should not be used as a substitute for professional mental health care. If you are in crisis, please contact emergency services or a crisis hotline.
We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last Updated" date at the top of this policy and notify you within the App. Continued use of the App after changes constitutes acceptance of the updated policy.
If you have questions about this Privacy Policy or your data:
| Data Type | Collected? | Stored Where | Shared With Third Parties? |
|---|---|---|---|
| Voice audio | Transcribed on device | Device only, never received by us | Never |
| Conversation text | Yes | Device only (encrypted) | Cloud AI while in Cloud mode, which is the starting mode, with personal details removed first |
| Spike companion state | Yes | Device only | Never |
| Emotional insights | Yes | Device only | Never |
| Photographs | Read on device, converted to text | Device only | Never |
| Billing record (subscribers) | Credit balance, keyed to Apple’s transaction identifier | Our servers | Never |
| Name, email, phone | No | N/A | N/A |
| Location data | No | N/A | N/A |
The nutrition label shown on the App Store is configured in App Store Connect and is the authoritative version. It is not restated here, so that the two cannot drift apart. What this policy describes is what the App does; the label is how that is categorized under Apple’s definitions.