What TellSign collects
- Message text you paste or type into the analysis screen.
- Text extracted from screenshots you upload. Text is read on your device first (nothing leaves your phone). Only if on-device reading fails — for example a rotated, low-quality, or unusual-script image — is the image itself sent to the same AI providers below to extract the text, then discarded. It is never stored.
- URLs decoded from QR codes you scan. The camera is used only to read the code; no photos are taken or stored.
- Your device's language setting, used only to return results in your language.
- A random, anonymous device identifier, used for the optional Family Guardian feature and fair-use limits. It is generated on your device and linked to no personal information.
- A push-notification token, only if you choose to act as a guardian for a linked device.
TellSign does not collect your name, email address, phone number, contacts, location, photos, or any account identifier — because TellSign does not require or support account creation.
How it's collected
Directly from your actions in the app — pasting, typing, uploading a screenshot, or scanning a QR code. Nothing is collected passively or in the background.
Who your data is sent to
When you submit a message for analysis, the message text and selected context tag are sent to the following third-party AI providers, for the sole purpose of generating your result:
- Anthropic (Claude models)
- OpenAI (GPT models)
- Google (Gemini models)
Each provider receives the same message text and processes it independently; TellSign's backend combines their responses into the single result shown to you. No provider receives more or different information than the others.
How it's used
Solely to generate the clear / watch / flag analysis and the explanation shown to you. Your content is not used for advertising, not sold, not shared with any party other than the three providers listed above, and not used to train TellSign's own models — TellSign does not train models.
Retention
- TellSign's backend stores nothing. Message text is processed in transit and discarded immediately after your result is returned. We keep no copy, no log of content, and no link to you.
- Third-party providers process the request on their own systems under their own API data policies. All three providers state that API inputs are not used to train their models by default and are retained only briefly for abuse monitoring. See
Anthropic,
OpenAI, and
Google for their current terms.
- Your history — results you choose to save — is stored only on your device, and is deleted when you uninstall the app or clear it in Settings.
Family Guardian
Guardian mode links two devices with consent so that a guardian receives a notification when a check on the protected device returns a "flag" result. Here is exactly what that involves:
- Anonymous device identifiers. Each device generates a random ID (e.g.
dev_x7k2…). It contains no personal information and is linked to no account, because there are no accounts.
- Pairing codes are 6 digits, single-use, and expire after 10 minutes.
- What our backend stores: the pair of random device IDs and the guardian device's push-notification token. Nothing else — no names, no phone numbers, no message content.
- What the guardian sees: only that a flagged check occurred on the linked device. Never the message, never the category, never any content.
- Unlinking is available to either side at any time and deletes the stored link immediately.
Threat Intercept
Threat Intercept classifies incoming text messages from senders not in your contacts and stops the ones that look like scams. This is the rare feature where the honest privacy disclosure is: there is nothing to disclose.
- All classification happens on your phone. On iPhone, the filter runs inside an Apple Message Filter Extension that has no internet access by platform rule — it cannot send anything anywhere, enforced by iOS itself, not merely promised by us. On Android, the same rules run locally inside the app's notification guard.
- No message body, no sender, and no metadata about any message is ever stored or transmitted — by the filter, by the app, or by our backend.
- The only thing that persists is a count — how many messages were stopped — kept on your device. On paid tiers, a paired family member you've linked through Family Guardian can be shown that count; never any content.
- You enable and disable the filter yourself in your phone's system settings, at any time.
Heads Up & Threat Radar
- Your Heads Up company list never leaves your phone. The app downloads a daily digest of circulating scams that is identical for everyone in a region, and your device does the matching locally. We can warn you about a fake message impersonating your bank while having no idea who you bank with.
- The only thing sent to fetch these feeds is your app language and, if you picked one, a coarse region (like “JP”) — no device identifier, no profile.
- Threat Radar's headlines come from public sources (government cyber centres and security press). Tapping one opens a short version inside TellSign: our server fetches and translates the article for everyone in a language — no account or identifier is attached to your tap. The original article is one tap away in your browser, subject to that site's own policies.
Decision Shield
- What you type into Shield is sent with your app language to generate the reply — analyzed in transit, never stored on our servers, the same as checks. Only the recent turns of the current conversation travel, and there is no account to attach them to.
- The conversation itself lives on your phone. Close it, and it's gone from our side entirely.
Daily training (Daily Drill & Pressure Pulse)
- Fetching the day's drill or pulse round sends only your app language and the local date — the same daily card is served to everyone.
- Your answers, streaks, scores, and saved rounds are stored only on your device. Your immunity score is computed on your phone and shared only if you explicitly turn on sharing with your linked circle — and then only the number travels, never an answer.
Community radar
To show warnings like "N people received this exact template this week," TellSign counts scam templates — without storing any message:
- Before counting, the message is stripped of all links, numbers, and email addresses, then reduced to an irreversible cryptographic fingerprint (SHA-256). The fingerprint cannot be turned back into the message.
- Our backend stores only the fingerprint and a counter, which automatically expire after two weeks.
- Counts are only shown once a template has been seen many times, so no individual check is identifiable.
Analytics on this website
tellsign.org uses Plausible, a privacy-friendly analytics service that uses no cookies and collects no personal data. The app itself contains crash reporting (Sentry) that captures technical error data only — never your message content.
Your choices
- You can use the Pattern Library and app settings without submitting anything for analysis.
- You can clear your local history at any time in Settings.
- You can contact support@tellsign.org with any privacy question.
Children
TellSign is not directed at children under 13, and we do not knowingly process data from them.
Changes
If this policy changes, the new version will be posted here with an updated effective date. Because we hold no contact information about you, we cannot notify you directly — check this page when in doubt.