Privacy Policy
Last updated 5 August 2026 · Effective 5 August 2026
Tellby is an audio travel guide. To play the right story at the right place we need to know where you are, and to keep your account and purchases working we need to know who you are. This page says exactly what we collect, why, where it goes, and how to get rid of it.
The short version. We collect your account details, your location while you're using the app, and anything you choose to publish. We don't sell your data, we don't run advertising trackers, and we don't build profiles for anyone else. You can delete your account at any time — §4 explains the few records we have to keep after that, and why.
1. Who we are
Tellby is operated by iai, a business registered in the Republic of Korea (business registration no. 213-08-81338). Representative: Changmyoung Kim, who is also our privacy contact and the Personal Information Protection Manager required by Korean law. We have not appointed a Data Protection Officer under Article 37 of the GDPR, because we are not required to. Contact: [email protected] — for privacy questions, put "Privacy" in the subject line.
2. What we collect
| Data | Why we need it | When |
|---|---|---|
| Account | Your email, display name and profile picture, received from Google or Apple when you sign in. Identifies your account and carries your purchases. | At sign-up |
| Device identifier | If you use the app as a guest, we create an account from a code derived from your device rather than from an email, so your plan and listening history survive restarting the app. We also store a device identifier with each sign-in token so you can sign out of a lost device. | Guest use, and at each sign-in |
| Location | Coordinates, so the app can play the story for the place you've reached. Sent to our server to record which stops you triggered and to avoid replaying the same one. | While a guide is active |
| Audio you record | Only if you create a guide, or if you speak in a live session. Stored so listeners can play it. | When you record or join a live session |
| Content you publish | Guides, plans, posts, photos, meetups. | When you publish |
| Messages | Direct messages and chat-room messages, so they can be delivered and shown to the people you sent them to. | When you send them |
| Purchases | Which plan you bought and how much of it is left. We never see your card number — Apple, Google and Stripe handle payment and tell us only whether it succeeded. | At purchase |
| Consent records | Which notice you agreed to, which version, and when. We keep these to be able to show that we obtained consent. | When you accept a notice |
| Reports you send or receive | What was reported, by whom, and what we decided. Needed to handle the report and to act on repeated problems. | On report |
| Crash reports | Technical details when something breaks, so we can fix it. | On error |
Location, specifically
Audio guides work by noticing that you've arrived somewhere. This happens while the app is open, and it keeps happening with the phone in your pocket for as long as a guide is playing — audio playback keeps the app running. We do not use "always" location permission, and the app stops looking for your position once playback ends and you leave the app. We store the stops you triggered, tied to your account, so a guide doesn't repeat itself. We do not track your continuous movement, keep a location history, or share your location with anyone. You can deny or revoke location permission at any time in your phone's settings; guides will then need a tap to play.
What we don't collect
- Card numbers, bank details or billing addresses
- Contacts, calendar, SMS or call history
- Advertising identifiers — there are no ad networks in this app, and the device identifier described above is used only to keep guest accounts and sign-in sessions working
- Any data from anyone below the minimum age in §7
3. Who else touches your data
Processors acting on our instructions
These companies run parts of the service for us and use your data only as we tell them to.
| Company | What for | Where |
|---|---|---|
| Neon | Database — accounts, content, purchases | United States |
| Fly.io | Application servers | Singapore, United States |
| Cloudflare | Audio and image storage, website delivery | Global |
| Google (Gemini) | Generating and narrating guide text | United States |
| Sentry | Crash reporting | United States |
| LiveKit | Live audio sessions, if you join one. Note that the other people in the session hear your voice. | Global |
Independent controllers
These companies decide for themselves how they use the data they get — for fraud prevention, account security and payment settlement — and their own privacy policies apply to that use. We can't instruct them, and we can't answer for them.
| Company | What for | Where |
|---|---|---|
| Apple | Sign in with Apple, App Store in-app purchases | Global |
| Google sign-in, Google Play in-app purchases | Global | |
| Stripe | Payment for real-world tours | United States |
We do not sell your personal information, and we do not share it for advertising. We hand data to authorities only where the law requires it.
Where your data lives
Our servers are outside your country in most cases — primarily the United States and Singapore. Using Tellby means your data is transferred and stored there.
- Who receives it, and where: the companies and countries in the two tables above. Each one's privacy contact is given in its own privacy policy.
- What is transferred: whichever of the items in §2 that company needs for its job. Neon receives accounts, content and purchase records; Sentry receives the technical details of an error and your internal account number; Google (Gemini) receives the place information used to generate a guide.
- When and how: at the moment you use the relevant feature, over an encrypted (TLS) network connection.
- Their purpose and retention: only the job described in the tables, for the periods in §4.
- You can refuse the transfer. Email [email protected] and we'll act on it. These companies are the infrastructure the service runs on, so refusing means we can't provide accounts, content or payments — we would close your account and refund the paid time you have not used. That is the only consequence; there is no other disadvantage.
- For users in the EEA, transfers to the United States and to Singapore rely on the European Commission's Standard Contractual Clauses with our providers. Neither country has an adequacy decision covering these transfers.
- For users in the United Kingdom, the same clauses apply together with the UK International Data Transfer Addendum.
- Korea has an EU adequacy decision, so transfers to us in Korea need no additional safeguard.
- You can ask for a copy of these safeguards at [email protected].
4. How long we keep it
When you delete your account we immediately anonymise it — your email, name and picture are removed and you can no longer sign in — and we then delete the underlying records within 30 days, except for the categories below, which we keep for the stated reason.
- Account and content — until you delete your account.
- Contract, withdrawal, payment and delivery records — 5 years, required by Korea's E-Commerce Act art. 6 and Framework Act on National Taxes art. 85-3. This includes the store receipt for each purchase, which contains an identifier issued by Apple or Google. Anything beyond what is needed to identify the transaction is pseudonymised. Pseudonymised data is still personal data, so we keep it separated from other information and restrict access to it; where a field can be fully anonymised we anonymise it and drop it from the retained set.
- Consumer complaint and dispute records — 3 years (E-Commerce Act art. 6).
- Advertising and labelling records — 6 months (E-Commerce Act art. 6).
- Creator earnings and payout records — 5 years, under the same tax rules.
- Consent records — kept after deletion, because their whole purpose is to show that consent was given and when. They hold the notice version, the timestamp and your internal account number, not your name or email.
- Reports and moderation decisions — up to 3 years, so we can recognise repeated abuse and answer appeals.
- Guides you sold to others — buyers keep access to what they paid for. Your name is removed and the guide is shown as anonymous.
- Messages you sent to other people — stay in the other person's conversation, shown from a deleted account.
- Crash reports — 90 days.
- Backups — copies may persist in encrypted backups for a limited period after deletion, and are overwritten on the normal backup cycle.
How we destroy it
When a retention period ends or the purpose is met, we destroy the data without delay, and we run that clear-out monthly. Data we must keep under another law is moved to a separate database or store so it isn't mixed with live data. Electronic files are deleted so they can't be recovered; anything printed is shredded or incinerated.
Cookies and automatic collection
The app does not use cookies or equivalent automatic collection to track you, and there are no advertising identifiers. Running the app stores a sign-in token and the device identifier described in §2 on your device; clearing the app's data or deleting the app removes them. The website at tellby.us has no visitor analytics.
Pseudonymised data
If we pseudonymise personal data for statistics or to improve the service, we keep the additional information that could re-identify you separately, with restricted access, and we never process it in order to identify a specific person again. We are not processing any pseudonymised data for this purpose at the moment.
5. Your rights
You can ask us to:
- Show you a copy of everything we hold about you
- Correct anything wrong
- Delete your account and its contents
- Send you your data — we do this by hand, by email, in a common file format such as JSON or CSV. There is no self-service export button in the app.
- Stop processing your data, or object to it
Delete your account in the app under My page → Account. For anything else — access, correction, deletion, or stopping processing — email [email protected]. That address is the intake point for those requests, handled by the representative. A legal guardian or an authorised agent may make a request on your behalf. We answer within 30 days and charge nothing; if we refuse a request we tell you why and how to challenge it.
If you want to complain
You can complain to your own data protection authority. In the EEA and the UK that is the supervisory authority where you live or work. In Korea:
- Personal Information Infringement Report Centre — privacy.kisa.or.kr · 118
- Personal Information Dispute Mediation Committee — kopico.go.kr · 1833-6972
- Personal Information Protection Commission — privacy.go.kr · 182
Depending on where you live you may also have rights under the GDPR (EEA/UK), under PIPA (Korea), or — if and to the extent it applies to us — under the CCPA (California), including the right to complain to your data protection authority. We do not sell or share personal information as those terms are defined in the CCPA, so there is no "Do Not Sell or Share My Personal Information" mechanism to offer.
Our legal bases for processing are: performing our contract with you (account, purchases, delivering guides, playing a guide at the place you have reached), your consent (background location and microphone — withdrawable at any time in your phone settings), our legitimate interest (keeping the service secure and working, and handling reports), and compliance with a legal obligation (tax and e-commerce record-keeping).
6. Security
Traffic is encrypted in transit (TLS). Passwords aren't stored because we don't use them — signing in goes through Google or Apple, or, for guests, through a code derived from your device. Sign-in tokens are kept in your device's secure keystore. Access to production data is limited to the operator. No system is perfectly secure; if a breach affects you, we'll tell you and the relevant authority without undue delay.
7. Children
Tellby is not for children. The minimum age is 16 in the EEA, Switzerland and the United Kingdom, 14 in the Republic of Korea, and 13 elsewhere — the same thresholds as §2 of the Terms. We do not process the personal data of a child under 14 without their legal guardian's consent, and we don't process location information for that age group at all. If you believe a child has given us information, email us and we'll check and delete it without delay.
8. Changes
If we change this policy we'll update the date above, and for anything significant we'll tell you in the app before it takes effect.
9. Contact
iai · Representative and privacy contact Changmyoung Kim · Business registration
no. 213-08-81338
[email protected] · Republic of Korea
Terms of Service · Delete Your Account