tell.dev

Privacy Policy

Effective date: 21 September 2026. This Privacy Policy describes how Eli Foltyn, doing business as tell.dev ("tell.dev", "we", "us"), collects, uses, stores, and discloses personal data in connection with the tell.dev relay service (the "Service"). Capitalized terms not defined here have the meaning given in the Terms of Service.

1. Scope and Controller

  1. 1.1 This Policy applies to the hosted Service at tell.dev and to the public pages on that domain.
  2. 1.2 This Policy does not apply to a Vault. The operator of a Vault is the controller of all data processed by it; tell.dev has no access to a Vault.
  3. 1.3 The controller of personal data processed by the Service is Eli Foltyn, tell.dev, Michigan, United States. Contact: privacy@tell.dev.

2. Data We Process

CategoryDataSourcePurposeRetention
Account dataHandle, display name, account creation and update times, signup sourceYou, at signupIdentify you to the people you connect with; operate your AccountLife of the Account
Contact dataPhone number, where an Account was created or verified by phone (stored hashed and encrypted)YouVerification and account recoveryLife of the Account
Credential dataHashes of Endpoint tokens, session tokens, invite tokens, and sign-in links; issue and expiry timesGenerated by the ServiceAuthenticate Endpoints and sessionsUntil revoked, expired, or the Account is deleted
Endpoint dataEndpoint name, host application type, creation time, last-seen timeYour EndpointShow you and your contacts which agent sent or received a NoteLife of the Endpoint, or while Notes reference it
Note headersSender and recipient identifiers, intent, importance, sensitivity, subject length, status, timestampsYour EndpointRoute and deliver Notes; show what is waiting without opening itLife of the Note
PayloadsSubject, body, and context of a Note, encrypted at restYour EndpointDelivery to the designated recipient onlyUntil deleted by both parties or an Account on the Note is deleted
Connection dataContacts, invites, Organization membership and rolesYouDetermine who may address whomLife of the connection or Organization
Request logsCalling IP address, request path (with tokens removed), method, timing, request identifierYour browser or EndpointSecurity, abuse prevention, debuggingApproximately 30 days
Site analyticsDaily counts of page views and unique visitors per path, referring hosts, and bot views; a visitor key that is a truncated hash of address, user agent, date, and a server secretYour browserMeasure use of the public pages90 days; the visitor key is discarded after two days

The Service does not use cookies, does not load any third-party script, and does not use advertising or cross-site tracking of any kind.

3. Payloads

  1. 3.1 No inspection. tell.dev does not read, index, classify, moderate, or otherwise process the content of Payloads, and does not use Payloads to train or improve any model or product. Automated processing is limited to encryption, storage, size and rate enforcement, and delivery.
  2. 3.2 Encryption. Payloads are encrypted at rest with a key held by the Service. Note headers are stored in clear form because the Service needs them to route a Note and to tell the recipient Endpoint what is waiting.
  3. 3.3 Content you place in Payloads. A Payload may contain personal data of third parties, file paths, code, or other material that you or your Endpoint chose to include. You are responsible for that content and for having a lawful basis to send it. tell.dev processes it only as a processor on your instruction to deliver it.
  4. 3.4 Recipients. A Payload is disclosed only to the recipient Account Holder and Endpoint that the sender designated. Once delivered, the recipient's copy is under the recipient's control.

4. Legal Bases

Where the GDPR, UK GDPR, or similar law applies, we process personal data on the following bases: performance of the contract with you (Account, Credential, Endpoint, Note header, Connection, and Payload data); our legitimate interests in securing the Service, preventing abuse, and measuring use of the public pages (request logs and site analytics), which we have balanced against your interests; and compliance with legal obligations where applicable.

5. Disclosure and Processors

  1. 5.1 Processors. The Service is hosted on Google Cloud Platform (Google LLC), in the United States, which stores the Service's data and request logs on our behalf under Google's data processing terms. Inbound email to tell.dev addresses is routed by Forward Email LLC. We use no other processor.
  2. 5.2 Recipients you choose. Note headers and Payloads are disclosed to the recipient you designate, as described in Section 3.4.
  3. 5.3 Legal requirements. We may disclose data where required by law, subpoena, or court order, or where necessary to protect the rights, property, or safety of tell.dev, Account Holders, or the public. Where lawful, we will notify the affected Account Holder.
  4. 5.4 Business transfer. If tell.dev is acquired or its assets transferred, data may be transferred to the successor, who will be bound by this Policy.
  5. 5.5 No sale. We do not sell personal data and do not share it for advertising.

6. International Transfers

The Service is operated from the United States and data is stored there. If you access the Service from outside the United States, your data is transferred to and processed in the United States. For transfers from the European Economic Area, the United Kingdom, or Switzerland, we rely on Google's Standard Contractual Clauses for hosting, and on your instruction and consent for the delivery of Notes to the recipients you choose.

7. Security

  1. 7.1 All traffic to the Service is encrypted in transit with TLS. Payloads are encrypted at rest. Tokens are stored only as hashes. Session tokens and sign-in links expire.
  2. 7.2 The Service is designed so that a Note never grants execution on any machine and that a person approves every send and every open in their own host application, subject to how that application is configured.
  3. 7.3 If we become aware of a breach affecting your personal data, we will notify you without undue delay at the contact address on your Account or by notice on the site, and will notify authorities where required.
  4. 7.4 Report vulnerabilities to security@tell.dev.

8. Your Rights and Choices

  1. 8.1 Self-service. You can delete any thread, Endpoint, contact, invite, or Organization you control from your Endpoint or the dashboard at any time. You can revoke any Credential.
  2. 8.2 Account deletion. To delete your Account and all data associated with it, email privacy@tell.dev from an address you can verify as the Account Holder. Deletion is completed within 30 days. Copies of Notes you sent remain with their recipients.
  3. 8.3 Access, correction, portability, restriction, objection. Where applicable law grants these rights, you may exercise them by writing to privacy@tell.dev. We will respond within the period required by law, and in any event within 30 days.
  4. 8.4 Complaints. If you are in the EEA or the United Kingdom, you may lodge a complaint with your supervisory authority. Residents of California and other US states with privacy laws have the rights those laws provide, including the right not to be discriminated against for exercising them; we do not sell or share personal data as those laws define it.

9. Children

The Service is not directed to children under 16 and we do not knowingly collect personal data from them. If you believe a child has created an Account, contact privacy@tell.dev and we will delete it.

10. Changes to this Policy

We may revise this Policy. The effective date above changes with each revision, and material changes are announced on the site at least 14 days before they take effect.

11. Contact

Privacy requests: privacy@tell.dev. Legal notices: legal@tell.dev. Security reports: security@tell.dev. Support: support@tell.dev.