Tellby exists to help families keep an older relative’s stories, told in their own voice. That means we handle something more personal than most apps: recordings of a real person talking about their life. This page explains, in plain language, what we collect, why, who we share it with, and the choices you and your storyteller have. It applies to the Tellby app at tellby.app, run by Richard Simms.
Who this covers
Tellby has three kinds of people:
- The organiser — usually an adult child or relative who sets up the family, invites the storyteller, and reviews every story before anyone else sees it.
- The storyteller — the person telling their stories by voice, often an older parent or grandparent.
- Family & listeners — the people the organiser chooses to share approved stories with.
This policy applies to all three. Where something only applies to one role, we say so.
What we collect
- Account details — the email address you sign in with, and any name or household details an organiser enters when setting up a family.
- Voice recordings and transcripts — the raw audio of every storytelling session, and a written transcript of what was said.
- Stories generated from those recordings — memory cards and letters written from the transcript, plus the underlying facts (people, places, events) our system extracts to keep track of what’s already been said. Every claim in a generated story traces back to the exact words that were recorded — we don’t let the AI add anything that wasn’t actually said.
- Payment information — if a family buys the memoir package, payment is handled entirely by Stripe. We never see or store a full card number.
- Usage and diagnostic data — basic product analytics and error reports, used only to find bugs and understand which parts of Tellby are working.
- Early-pilot recruitment responses — if you apply for the pilot or answer a storyteller invitation, we collect the contact and invitation-matching details shown on that form. The storyteller decline path does not ask for contact details; any optional decline reason stays with the pilot team and is not shared with family.
Consent comes first
Before a storyteller’s first session, they’re asked — in plain, spoken language — whether it’s okay to record their stories and share them with the family the organiser has chosen. That “yes” has to be explicit; silence doesn’t count. At any point, a storyteller can:
- Skip any question, with no explanation needed.
- Stop a session at any time.
- Say a subject should never come up again — once that’s recorded, our system is built to permanently avoid asking about it, forever.
- Change their mind later about a story being shared. Telling the organiser is enough — no forms.
Withdrawing consent to share a story with family takes it out of family view immediately; the recording itself stays under the recording consent until it is separately withdrawn.
Deleting recordings that already exist is a separate, deliberate step, because it can’t be undone for the rest of the family. An organiser can ask for it from their Settings page, and either of you can ask us directly. A storyteller who is able to confirm has to confirm it themselves as well — we won’t delete someone’s recordings on another person’s say-so alone — so email us and we’ll arrange that confirmation with them.
Where a storyteller has died, or can no longer use the device to confirm, the organiser can ask on their own and tell us why. In that case recording stops immediately, the existing stories stay readable for seven days so the decision can still be reversed, and after that they are permanently deleted.
The approval gate
Nothing a storyteller says reaches the wider family automatically. Every story is reviewed and explicitly approved by the organiser first — this is enforced by our database, not just a setting someone could accidentally switch off.
How we use this information
We use it to run the service: turning a spoken session into a readable, editable story; showing the organiser what’s ready to review; sharing approved stories with the family they choose; and keeping track of the cost of running each session so we can keep pricing fair. We don’t sell your data, and we don’t use your family’s recordings or stories to train anyone’s general-purpose AI models — the AI providers we use process this content only to generate your family’s own stories.
Who we share it with
Running Tellby means using a small number of specialist providers to do specific jobs. None of them get more than they need to do that job:
- OpenAI — powers the live voice conversation and its transcript during a session.
- OpenRouter — turns a session transcript into structured story material (people, places, events).
- Vercel — hosts the app, and its AI Gateway is used to polish the wording of generated stories and letters.
- Supabase — our database, file storage, and sign-in system. Almost everything above is ultimately stored here, protected by access rules enforced at the database level.
- Amazon Web Services (AWS) — keeps encrypted backup copies of recordings, stories, and the supporting records needed to recover Tellby after a serious loss or failure. The backup objects are stored separately from our main storage in AWS’s Sydney region and are used only for disaster recovery.
- Stripe — handles payment for the memoir package. We never see full card details.
- Resend — sends account and story-ready emails, and carries early-pilot applications and storyteller invitation responses to the Tellby pilot team when someone uses a public pilot form.
- PostHog — product analytics, used to improve reliability. It records how the app is used, not what is said: story text and on-screen wording are masked before anything is sent.
Most of these providers operate infrastructure outside Australia (largely in the United States), so recordings and stories may be processed on servers overseas as part of delivering the service.
How long we keep it
Raw audio and transcripts are kept as the lasting record of what was said, for as long as the family wants Tellby to hold them.
We also keep encrypted backup copies, separate from Tellby’s main systems, so we can recover recordings, stories, and the records that support them after a serious loss or failure. Access to these backups is restricted to authorised people and systems involved in disaster recovery.
Once a deletion is confirmed as described above, normal app access to those recordings and the stories made from them stops straight away. We then remove those recordings and stories from Tellby’s live systems through our verified deletion process. An encrypted backup copy may still contain them for no more than 30 days after confirmation, while the relevant backup expires or is removed.
Before information restored from a backup can be made available in Tellby, our recovery process checks and applies deletion records so recordings or stories already deleted are not returned to normal app access.
One thing does stay. We keep a short record that consent was given and later withdrawn: what was agreed to, which version of the wording was used, and when. It holds no name, email, date of birth, or anything that was said, and the person it belonged to is no longer named anywhere in it. We keep it because it is the only proof that a recording was made with permission, and that the permission was withdrawn when it was asked for.
Deleting an account is not the same as deleting the recordings, and which one you get depends on whose account it is. When a storyteller deletes their own account, their recordings and stories go with it, through the same confirmed process described above. When an organiser deletes theirs, it removes their sign-in and their access — the recordings belong to the storyteller and stay, unless the storyteller’s stories are deleted as well. If you want both, ask for the storyteller’s stories to be deleted first.
Your rights
You can ask us to show you what we hold about you or a storyteller you organise for, correct anything that’s wrong, or delete it. Organisers can see what their storyteller has agreed to, and ask for that storyteller’s stories or their own account to be deleted, from the Settings page. For anything else, get in touch using the details below and we’ll act on it as quickly as we reasonably can. If you’re in Australia and unhappy with how we’ve handled a privacy concern, you can also contact the Office of the Australian Information Commissioner (OAIC).
Security
Access to stories is enforced by row-level database rules, not just app-level checks — the same rule that keeps a story private until approved also stops one family from ever seeing another family’s data. Credentials used to talk to our voice provider are short-lived and minted per session; the underlying API keys never reach a storyteller’s or organiser’s device.
Storytellers who need extra support
Tellby is built for adults who can understand and give their own consent to being recorded. If a storyteller has a legal decision-maker acting on their behalf — for example in a residential aged-care setting — please contact us before starting sessions; Tellby’s consent flow doesn’t yet have a dedicated path for substitute decision-makers, and we want to get that right rather than assume it.
Changes to this policy
If we materially change how we handle recordings or stories, we’ll update this page and change the date at the top. For anything that affects an existing consent, we’ll also tell the organiser directly.
Contact
Questions, requests, or concerns about privacy: email [email protected].