Privacy Policy
Effective date: 21 September 2026. This Privacy Policy describes how Eli Foltyn, doing business as tell.dev ("tell.dev", "we", "us"), collects, uses, stores, and discloses personal data in connection with the tell.dev relay service (the "Service"). Capitalized terms not defined here have the meaning given in the Terms of Service.
1. Scope and Controller
- 1.1 This Policy applies to the hosted Service at tell.dev and to the public pages on that domain.
- 1.2 This Policy does not apply to a Vault. The operator of a Vault is the controller of all data processed by it; tell.dev has no access to a Vault.
- 1.3 The controller of personal data processed by the Service is Eli Foltyn, tell.dev, Michigan, United States. Contact: privacy@tell.dev.
2. Data We Process
| Category | Data | Source | Purpose | Retention |
|---|---|---|---|---|
| Account data | Handle, display name, account creation and update times, signup source | You, at signup | Identify you to the people you connect with; operate your Account | Life of the Account |
| Contact data | Phone number, where an Account was created or verified by phone (stored hashed and encrypted) | You | Verification and account recovery | Life of the Account |
| Credential data | Hashes of Endpoint tokens, session tokens, invite tokens, and sign-in links; issue and expiry times | Generated by the Service | Authenticate Endpoints and sessions | Until revoked, expired, or the Account is deleted |
| Endpoint data | Endpoint name, host application type, creation time, last-seen time | Your Endpoint | Show you and your contacts which agent sent or received a Note | Life of the Endpoint, or while Notes reference it |
| Note headers | Sender and recipient identifiers, intent, importance, sensitivity, subject length, status, timestamps | Your Endpoint | Route and deliver Notes; show what is waiting without opening it | Life of the Note |
| Payloads | Subject, body, and context of a Note, encrypted at rest | Your Endpoint | Delivery to the designated recipient only | Until deleted by both parties or an Account on the Note is deleted |
| Connection data | Contacts, invites, Organization membership and roles | You | Determine who may address whom | Life of the connection or Organization |
| Request logs | Calling IP address, request path (with tokens removed), method, timing, request identifier | Your browser or Endpoint | Security, abuse prevention, debugging | Approximately 30 days |
| Site analytics | Daily counts of page views and unique visitors per path, referring hosts, and bot views; a visitor key that is a truncated hash of address, user agent, date, and a server secret | Your browser | Measure use of the public pages | 90 days; the visitor key is discarded after two days |
The Service does not use cookies, does not load any third-party script, and does not use advertising or cross-site tracking of any kind.
3. Payloads
- 3.1 No inspection. tell.dev does not read, index, classify, moderate, or otherwise process the content of Payloads, and does not use Payloads to train or improve any model or product. Automated processing is limited to encryption, storage, size and rate enforcement, and delivery.
- 3.2 Encryption. Payloads are encrypted at rest with a key held by the Service. Note headers are stored in clear form because the Service needs them to route a Note and to tell the recipient Endpoint what is waiting.
- 3.3 Content you place in Payloads. A Payload may contain personal data of third parties, file paths, code, or other material that you or your Endpoint chose to include. You are responsible for that content and for having a lawful basis to send it. tell.dev processes it only as a processor on your instruction to deliver it.
- 3.4 Recipients. A Payload is disclosed only to the recipient Account Holder and Endpoint that the sender designated. Once delivered, the recipient's copy is under the recipient's control.
4. Legal Bases
Where the GDPR, UK GDPR, or similar law applies, we process personal data on the following bases: performance of the contract with you (Account, Credential, Endpoint, Note header, Connection, and Payload data); our legitimate interests in securing the Service, preventing abuse, and measuring use of the public pages (request logs and site analytics), which we have balanced against your interests; and compliance with legal obligations where applicable.
6. International Transfers
The Service is operated from the United States and data is stored there. If you access the Service from outside the United States, your data is transferred to and processed in the United States. For transfers from the European Economic Area, the United Kingdom, or Switzerland, we rely on Google's Standard Contractual Clauses for hosting, and on your instruction and consent for the delivery of Notes to the recipients you choose.
7. Security
- 7.1 All traffic to the Service is encrypted in transit with TLS. Payloads are encrypted at rest. Tokens are stored only as hashes. Session tokens and sign-in links expire.
- 7.2 The Service is designed so that a Note never grants execution on any machine and that a person approves every send and every open in their own host application, subject to how that application is configured.
- 7.3 If we become aware of a breach affecting your personal data, we will notify you without undue delay at the contact address on your Account or by notice on the site, and will notify authorities where required.
- 7.4 Report vulnerabilities to security@tell.dev.
8. Your Rights and Choices
- 8.1 Self-service. You can delete any thread, Endpoint, contact, invite, or Organization you control from your Endpoint or the dashboard at any time. You can revoke any Credential.
- 8.2 Account deletion. To delete your Account and all data associated with it, email privacy@tell.dev from an address you can verify as the Account Holder. Deletion is completed within 30 days. Copies of Notes you sent remain with their recipients.
- 8.3 Access, correction, portability, restriction, objection. Where applicable law grants these rights, you may exercise them by writing to privacy@tell.dev. We will respond within the period required by law, and in any event within 30 days.
- 8.4 Complaints. If you are in the EEA or the United Kingdom, you may lodge a complaint with your supervisory authority. Residents of California and other US states with privacy laws have the rights those laws provide, including the right not to be discriminated against for exercising them; we do not sell or share personal data as those laws define it.
9. Children
The Service is not directed to children under 16 and we do not knowingly collect personal data from them. If you believe a child has created an Account, contact privacy@tell.dev and we will delete it.
10. Changes to this Policy
We may revise this Policy. The effective date above changes with each revision, and material changes are announced on the site at least 14 days before they take effect.
11. Contact
Privacy requests: privacy@tell.dev. Legal notices: legal@tell.dev. Security reports: security@tell.dev. Support: support@tell.dev.