Privacy Policy

Effective April 8, 2026 · Last updated August 27, 2026

1. Introduction

Tellspike ("we," "our," or "us") provides an AI-powered voice companion for personal reflection and emotional well-being through the Tellspike iOS application ("the App"). This Privacy Policy explains what data we collect, how we use it, and the choices you have.

We designed Tellspike with privacy at its core. Everything that can run on your device does, and we never sell your data. Section 4.2 describes what goes to the cloud and when.


2. Information We Collect

2.1 Voice Recordings

2.2 Journal Entries and Conversations

2.3 Usage Analytics

Tellspike does not collect usage analytics, crash reports, or performance telemetry. We do not implement any first-party analytics, and we do not integrate any third-party analytics or crash reporting SDK (no Firebase, Mixpanel, Amplitude, Segment, Sentry, Crashlytics, or equivalent).

If you have separately opted in to share analytics with Apple under iOS Settings → Privacy & Security → Analytics & Improvements, iOS may include Tellspike in what it sends to Apple. That is a relationship between you and Apple; Tellspike neither asks for that data nor receives it. You can disable this at any time in iOS Settings.

2.4 Information We Do NOT Collect


3. On-Device AI Processing

Tellspike prioritizes on-device AI so your conversation text stays on your phone by default. On-device processing involves no data transmission and is not disclosed in our App Store privacy nutrition label because the data never leaves the device.

Apple Foundation Models: Answers are generated on your device by the language model built into iOS. No conversation data is sent to any server.

Tellspike requires Apple Intelligence and does not run without it. On a device that cannot run it, the app explains why and stops, rather than quietly sending your conversation somewhere else.

3.1 Photos

You can attach a photo to a message, either from your photo library or by taking one with the camera. Tellspike opens the camera only when you choose to, never on its own. When you do, your device reads it using Apple’s Vision framework and produces text: any words legible in the image, and up to three labels for what is in it. Spike responds to that text.

The photo itself never leaves your device, in either mode. This is enforced by the type system rather than by policy: the stored photo type is deliberately not encodable, so it cannot be serialized into a request body at all. A test fails the build if that ever changes.


4. Cloud AI Providers and Your Control

4.1 Providers We Use

When cloud AI is needed, Tellspike routes requests to one of these named providers:

No other cloud AI providers are used without updating this policy and notifying you in the App.

4.2 When Cloud AI Is Used

You control cloud AI through Tellspike’s privacy mode. Switching to Private stops it immediately and completely:

Mode Cloud AI What Happens
Private OFF All processing stays on your device. Nothing leaves your phone. No internet required.
Cloud ON, with protections Conversation text is sent to a cloud provider with personal details removed first. You must explicitly switch this on.

Default: The App defaults to Private. You must actively switch to Cloud to enable cloud AI processing. You can switch back at any time, and cloud processing stops immediately. Under every message that went to the cloud there is a marker you can tap to read the exact text that left your device.

You can see what was sent. Every message that went to the cloud carries a marker underneath it. Tap it and it shows the exact text that was handed to the provider for that turn, taken from the string given to the network layer rather than reconstructed afterwards. A message handled on your device carries no marker, so the absence of one means nothing left.

4.3 What Is Sent to Cloud Providers

In Cloud mode:

4.4 What Is NOT Sent

4.5 What We Don't Claim to Protect Against

We want to be straight with you about the limits of what removing direct identifiers can do. In Cloud mode, we strip names, phone numbers, addresses, and similar identifying tokens from your conversation text before it leaves your phone. That protects against the most common ways a stray log line gets traced back to a real person. What it does not do is mask how you write. Academic research has shown that writing style itself can act as a fingerprint: word choices, sentence rhythms, and topic patterns can re-identify an author from text that has had all the obvious identifiers removed, given enough samples. We're not aware of any consumer AI app that defends against this, and we don't claim to either. If you're sending text to a cloud provider for any reason, treat it the way you'd treat sending a postcard: scrubbed of the name and return address, but still in your own handwriting. The free, on-device tier sidesteps this entirely because nothing leaves the phone.


5. Data Storage and Security

5.1 Local Storage

5.2 What Is and Is Not on Our Servers

Your conversations are not. Message text, Spike’s state, and your insights live on your device. They are never uploaded, in either mode. In Cloud mode the anonymized text of a single turn is sent to the provider to generate that one reply, and you can read exactly what was sent by tapping the marker under that reply.

If you have never purchased anything, we hold nothing at all. The free tier makes no network requests. This is enforced by a test that fails the build if any outbound request is made.

If you subscribe or buy credits, a billing record exists. It is keyed to the transaction identifier Apple issues for your purchase, and it holds your credit balance so that usage can be metered and refunds honored. It does not hold your name, email address, phone number, or any conversation content. Tellspike has no login: it never asks you to create an account and there is no password to set. Your App Store purchase is the credential, which also means that if a subscription lapses, this device may no longer be able to prove a billing record is yours even though the record still exists. Contact privacy@tellspike.com and we will delete it.

5.3 Data Retention

Data Type Retention How to Delete
Conversations Until you delete them Settings > Reset Tellspike, or uninstall the App
Spike companion state Until you delete Settings > Reset Tellspike, or uninstall the App
Cloud provider logs Up to 30 days (provider policy) Deleted automatically by provider
Billing record (subscribers only) While your subscription or credit balance is active Settings > Delete billing account, which starts a 30-day grace period

Deleting the App removes all locally stored data, including conversations, Spike companion state, and preferences.


6. Data Sharing and Third Parties

We Do Not Sell Your Data

We never sell, rent, or trade your personal information, conversation data, or usage patterns to any third party for any purpose.

Limited Third-Party Sharing

Third Party What Is Shared When Your Control
Anthropic (Claude API) Anonymized conversation text Cloud mode only Switch back to Private to stop
OpenAI (GPT API) Anonymized conversation text Cloud mode only Switch back to Private to stop
Apple (OS-level, not via Tellspike) Whatever iOS diagnostics you opted into at the OS level, routed entirely by Apple. Tellspike does not push anything to this pipeline. If you opted in during iOS setup iOS Settings > Privacy & Security > Analytics & Improvements
Law enforcement As required by valid legal process Court order, subpoena, or legal obligation N/A

We do not use third-party advertising networks, data brokers, or social media tracking pixels.


7. Children's Privacy


8. Your Rights and Choices

8.1 Privacy Mode Control

You have full control over how your data is processed:

8.2 Data Deletion

8.3 California Residents (CCPA/CPRA)

California residents have the right to:

8.4 European Residents (GDPR)

If you are in the European Economic Area, you have the right to access, rectify, erase, restrict, or port your personal data, and to lodge a complaint with a supervisory authority. Our legal basis for processing is your explicit consent (you must switch on Cloud mode yourself; Private is the default).

8.5 Wellness Disclaimer

Tellspike is a personal wellness and reflection tool. It is not a medical device, does not provide medical advice, diagnosis, or treatment, and is not a covered entity under HIPAA. Tellspike should not be used as a substitute for professional mental health care. If you are in crisis, please contact emergency services or a crisis hotline.


9. AI-Specific Disclosures

9.1 AI-Generated Content

9.2 AI Model Training

9.3 Emotional Well-Being Safeguards


Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the "Last Updated" date at the top of this policy and notify you within the App. Continued use of the App after changes constitutes acceptance of the updated policy.


Contact Us

If you have questions about this Privacy Policy or your data:


Summary

Data Type Collected? Stored Where Shared With Third Parties?
Voice audio Transcribed on device Device only, never received by us Never
Conversation text Yes Device only (encrypted) Cloud AI while in Cloud mode, which is the starting mode, with personal details removed first
Spike companion state Yes Device only Never
Emotional insights Yes Device only Never
Photographs Read on device, converted to text Device only Never
Billing record (subscribers) Credit balance, keyed to Apple’s transaction identifier Our servers Never
Name, email, phone No N/A N/A
Location data No N/A N/A

App Store Privacy Nutrition Label

The nutrition label shown on the App Store is configured in App Store Connect and is the authoritative version. It is not restated here, so that the two cannot drift apart. What this policy describes is what the App does; the label is how that is categorized under Apple’s definitions.