Privacy

Privacy, plainly

Your family trusted us with someone's life story. That's not something we take lightly. This page says — in plain words, not legal fog — what we collect, why, who ever sees it, and how you stay in control.

This policy is issued by [CONFIRM: legal entity name, e.g. "hist.life, Inc."], [CONFIRM: entity type and place of incorporation], and is governed by the laws of [CONFIRM: governing law / jurisdiction for disputes]. Last updated: [CONFIRM: date this policy was finalized].

The short version

  • Your family's stories are never sold.
  • Product analytics never sees what you or your storyteller said — every word on screen is hidden from analytics recordings, everywhere, always.
  • Audio and words are sent to our AI partner only to transcribe the interview and guide the next question. [CONFIRM: whether that content is ever used to train AI models (ours or the provider's) — critical, do not guess]
  • The person being interviewed never needs an account and is never tracked.
  • You can ask us to delete an interview, an account, or an archive, any time.

What we collect

Only what it takes to run the interview and keep the archive, specifically:

  • The stories themselves — audio recordings, live transcripts, chat messages, and any photos you or your storyteller add. This is the heart of what tellall keeps.
  • Story organization — story cards, life periods, and the names of people and places mentioned, so the archive can be browsed by timeline, photo, or person.
  • The storyteller's basic details — a name, and (if given) an email, attached to an interview session so we know whose story is whose.
  • Account details — name and email address, for whoever signs in to manage interviews and the archive.
  • Usage information — device/browser info, IP address, and product-usage events (for example, "an interview was started") — never the content of the story itself.
  • If something breaks — our error-monitoring tool may record technical details (your IP address, browser information) and, for a small sample of visits, or any visit where an error happens, a short replay of what was on screen, so our engineers can see and fix the problem. This is separate from product analytics above, and unlike analytics, it is not guaranteed to hide on-screen text — it exists purely to help us catch and fix bugs.

Why we collect it

  • To run the interview — transcribing, and quietly suggesting the next question.
  • To keep the archive organized and browsable for your family.
  • To keep tellall working, secure, and improving (bug fixes, abuse prevention).
  • To handle billing, for paid plans.

Who we trust with it

We don't build our own servers, email system, or AI from scratch. We use a small number of specialist companies to run tellall, and each only sees what it needs to do its one job:

  • Convex — hosts our database and all file storage. Your audio, photos, and transcripts live here.
  • better-auth (run inside our own Convex database, not a third-party auth service) — manages sign-in. We never see or store your password in plain form.
  • Vercel AI Gateway — receives interview audio and text to transcribe it and generate the interviewer's next question or voice reply. See "The AI part" below.
  • PostHog — product analytics, only once you say yes. Never sees your story's content (see "Analytics & cookies" below).
  • Sentry — error monitoring, so we notice and fix bugs quickly.
  • Resend — delivers account email: sign-in verification, password resets, and invitations.
  • Polar — processes payment for paid plans. tellall never stores your card number.

[CONFIRM: whether data processing agreements (DPAs) are in place with each vendor above, and the exact legal names/entities to cite]

The AI part, specifically

Because this is what people worry about most:

When you interview together, chat, or use voice mode, your audio and words are sent through the Vercel AI Gateway to an AI model so it can turn speech into a transcript, suggest the next gentle question, and — in chat or voice mode — hold up its end of the conversation.

[CONFIRM: is any interview audio or transcript ever used to train AI models, ours or our provider's? State the actual answer here plainly once confirmed — this is the single most important trust fact on this page]

[CONFIRM: how long the AI Gateway / model provider retains submitted audio and text beyond generating a response]

Analytics & cookies — you choose

  • The first time you visit, we ask before turning on analytics. Nothing is tracked before you say yes.
  • If you say no, we don't set tracking cookies at all — only anonymous, cookie-free counts.
  • Even when analytics is on, it never sees the words in your story — on-screen text is deliberately hidden from analytics recordings, everywhere in the product, always.
  • A storyteller opening a private interview link is never identified or tracked. Only signed-in family members managing the archive are.
  • Signing in sets a session cookie so you stay logged in. [CONFIRM: exact cookie name(s) and duration, for a cookie table if your jurisdiction requires one]

How long we keep it

[CONFIRM: the intended retention period for stories, audio, and transcripts — and whether "kept until you ask us to delete it" (current behavior — there is no automatic deletion timer in the product today) is the actual policy, or a fixed retention limit should be documented instead]

[CONFIRM: what happens to a storyteller's recording if the interview link is never claimed by a family account, and how long backups are kept after deletion]

Your rights & control

  • Access — ask us what we hold about you or your family's archive.
  • Correction — ask us to fix anything that's wrong.
  • Deletion — ask us to permanently delete an interview, an account, or an entire archive.
  • Portability — [CONFIRM: do we offer an export of story cards, audio, or transcripts on request? Describe the process]

Right now, these are handled by writing to us directly at [CONFIRM: privacy / data-deletion contact email]. We aim to respond within [CONFIRM: response-time commitment, e.g. "5 business days"].

[CONFIRM: GDPR (EU/UK) legal basis for processing + data-subject rights language, if you have or expect users in the EU/UK]

[CONFIRM: CCPA/CPRA (California) stance and "Do Not Sell or Share My Personal Information" statement, if you have or expect California users]

Security

Connections to tellall are encrypted (HTTPS) everywhere, and access to raw recordings is limited to what the product needs to function.

[CONFIRM: any additional claims worth stating here — encryption-at-rest specifics, security certifications (e.g. SOC 2) — only if verified, never asserted by default]

Children

tellall isn't directed at children, though the stories we help capture are often about a storyteller's own childhood.

[CONFIRM: age-restriction / COPPA stance, if minors could plausibly be storytellers or account holders]

Changes to this policy

We'll post updates here. If a change is significant, we'll let you know [CONFIRM: via email / in-app notice — pick one].

Contact

Questions, requests, or just want to talk to a person? Write to [CONFIRM: contact email], or by mail at [CONFIRM: company legal name and registered address].

Privacy — How we protect your family's stories | hist.life