Legal
Privacy Policy
How TellTell collects, uses, protects, shares, and retains information.
Effective September 3, 2026
1. Scope and privacy roles
TellTell LLC (“TellTell,” “we,” “us,” or “our”) provides group-email products, websites, and services (the “Service”). This Privacy Policy explains how we collect, use, disclose, retain, and protect personal information. It is a notice of our practices, not a request for blanket consent. Where consent is the appropriate legal basis, we request it separately.
TellTell determines how it uses organizer account, website, billing, and direct-support information and acts as a controller or business for that information. For member directories, relationships, groups, and messages managed by a customer organization, TellTell generally acts as that organization's processor or service provider and follows its instructions. Our Data Processing Addendum describes those obligations.
Our Terms of Use and Data Processing Addendum provide additional contractual information.
2. Changes to this Policy
We may update this Policy prospectively. We will post the current version with its effective date and provide reasonable notice of material changes. When applicable law requires consent, we will request it before applying the relevant new practice.
3. Age and parental consent
A person must be at least 18, or at least 16 with a parent or legal guardian's consent, to create or administer a TellTell account. The Service is not directed to children under 16, and we do not knowingly allow them to create accounts. If we learn that an ineligible child created an account, we will take appropriate steps to close it and delete the information.
Organizations may use TellTell to send ordinary group email to younger members who do not have TellTell accounts. The organization determines what member information to provide and is responsible for required notices, authority, and parental consent. We do not knowingly sell or share personal information of people under 16.
4. Information we collect
Account and organization information. We may receive from a third-party authentication provider, including Apple, Google, Meta (Facebook), Microsoft, or another provider TellTell supports, your provider account identifier, name, profile image, email address, organization settings, roles, time zone, session and security events, and account activity.
Customer-managed information. Organizers may provide member names, email addresses, custom fields, tags, relationships, roles, memberships, sender permissions, reply settings, suppressions, and delivery state. Do not place Social Security numbers, government identification, financial credentials, passwords, medical records, biometric identifiers, precise geolocation, or other highly sensitive information in custom fields or messages unless TellTell expressly agrees in writing.
Automatic profile images. When a customer enables automatic profile images, TellTell may use a signing-in person's image from a supported identity provider or send a one-way SHA-256 representation of a directory person's normalized primary email to Gravatar to check for a public profile image. TellTell retrieves and stores a private, normalized copy; it does not expose the email or hash to the customer's browser. Customers can disable automatic images for their account, and administrators can hide one for a specific person.
Mail information. We process sender, recipient, group, and account identifiers; message subjects and content; timestamps; size and recipient counts; policy and delivery results; bounces, complaints, and unsubscribe state; and provider identifiers. Message bodies and attachments pass through our systems for inspection and delivery and are not intended to be a permanent TellTell archive.
Billing and support. Stripe handles payment-card data. We receive billing references, subscription status, billing contact details, and transaction information. Support may include messages submitted through our contact form or support tools, screenshots you choose to send, contact details, device and page information, timestamps, and diagnostic records. Google helps us protect the public contact form from automated abuse and deliver submitted messages to TellTell's support mailbox.
Website and device information. Hosting, security, and browser technologies may collect IP address, requested and referring pages, browser and device type, language, date and time, session identifiers, and similar technical data.
5. Categories of information and practices
The following table describes our practices during the 12 months before this Policy's effective date. A category may include information protected as personal or sensitive under some state laws.
| Category and examples | Sources | Purposes | Recipients |
|---|---|---|---|
| Identifiers and account data: name, email, identity-provider identifier, IP address, session identifiers | You, your organization, your authentication provider, and your device | Account creation, authentication, support, security, notices | Identity, hosting, security, and support providers |
| Organization directory and relationships: members, groups, roles, custom fields, permissions | You and customer organizers | Manage directories, authorize senders, route group email | Hosting and mail providers; authorized organizers and recipients as configured |
| Profile-image data: provider image, normalized image copy, and a one-way representation of the primary email used for Gravatar lookup | Authentication providers, customer organizers, and Gravatar | Display optional account-scoped directory images | Hosting providers and Gravatar when the feature is enabled |
| Commercial and billing information: plan, transaction, billing contact, Stripe references | You and Stripe | Checkout, subscriptions, accounting, fraud prevention | Stripe, hosting providers, professional advisers when needed |
| Internet and device activity: pages, browser, device, referral, timestamps, diagnostics | Your browser and service systems | Operate, secure, troubleshoot, and improve the Service | Hosting, security, and support providers |
| Communications and support: messages, feedback, optional screenshots | You and people communicating through the Service | Provide email delivery and support; resolve disputes and errors | Mail and support providers; intended recipients |
| Operational and security records: delivery events, suppressions, audit events, abuse signals | Service systems, providers, organizers, recipients | Deliver messages, honor choices, prevent abuse, audit and secure the Service | Hosting, mail, and security providers; authorities when legally required |
We do not sell personal information or share it for cross-context behavioral advertising. We do not use sensitive personal information to infer characteristics. We retain each category only as long as reasonably necessary for the purposes described below.
6. How we use information
We use personal information to provide, route, secure, personalize, and support the Service; authenticate users and enforce permissions; administer subscriptions; prevent abuse and investigate errors; audit activity; communicate about security, billing, service, and policy matters; comply with law; and improve reliability and usability.
We may use aggregated or de-identified information only when it cannot reasonably identify a person or customer. We maintain it in de-identified form and do not attempt to re-identify it except to test our de-identification methods or as required by law. We do not use Customer Content to train general-purpose artificial-intelligence models.
7. How we disclose information
We disclose information to service providers that help with identity, hosting, email processing and delivery, billing, security, and support; to authorized organizers and intended email recipients according to customer settings; to professional advisers subject to confidentiality; as required by law; and in connection with a merger, financing, acquisition, or sale, subject to appropriate protections.
Service providers may use information only to provide contracted services and as permitted by law. The current provider list and change procedure are included in the Subprocessors section of our DPA. Credit-card information is handled by Stripe rather than stored by TellTell.
8. Retention and deletion
We retain information for as long as reasonably necessary to provide the Service, maintain customer-visible history, honor suppressions and user choices, secure and troubleshoot the Service, administer billing, comply with law, and resolve disputes. Retention depends on the information's nature, sensitivity, purpose, account status, legal requirements, and technical constraints.
- Message bodies and attachments are ordinarily transient and deleted after processing; short-lived operational queues and records expire under internal schedules.
- Customer-visible directory, configuration, and message-delivery history generally remains while an account is active or as directed by the customer.
- Cached automatic profile images are removed when the related person or account is deleted, the image is replaced, or an administrator disables the applicable automatic image, subject to bounded cleanup and backup schedules.
- Removed records and closed accounts may remain during a brief restoration period described in the Terms, after which deletion begins.
- Encrypted backups, provider queues, billing records, suppression records, security records, and deletion receipts expire or are retained under applicable operational, legal, fraud-prevention, and accounting schedules.
Deletion from active systems may not immediately remove information from immutable backups or provider systems. We isolate and protect retained information and delete or anonymize it when the applicable period ends, unless a legal hold or other lawful exception applies.
How to delete a personal TellTell login
- Sign in to TellTell with the provider identity you use.
- Open User settings and select General.
- Choose Delete personal login and follow the confirmation steps.
- Reauthenticate with the same provider to finish deletion.
This removes the personal login identity and signs out its sessions. TellTell may retain bounded deletion receipts, security records, billing records, suppressions, or backups where required for legal, security, fraud-prevention, or operational purposes.
Customer organization data
Deleting a personal login does not independently delete information controlled by a customer organization, such as its directory, groups, delivery history, or billing records. Contact that organization's administrator to request changes to customer-controlled information. Account administrators can use TellTell's separate account-closure process for organization data.
Request deletion help
If you cannot access your TellTell login or need help with a deletion or privacy request, email legal@telltell.co. Include the email address associated with the request, but do not send passwords, provider tokens, or sensitive identity documents unless we specifically request a secure verification method.
10. U.S. state privacy rights
Depending on where you live and subject to legal exceptions, you may have rights to know or access personal information; receive information about categories, sources, purposes, and recipients; correct inaccuracies; delete information; obtain a portable copy; opt out of sale, targeted advertising, or certain profiling; limit certain uses of sensitive information; appeal a denied request; and receive equal service without unlawful discrimination.
TellTell does not sell personal information or share it for cross-context behavioral advertising and therefore does not require a “Do Not Sell or Share” link for its current practices. We honor applicable Global Privacy Control signals by keeping optional advertising technologies off for that browser. We do not knowingly sell or share personal information of people under 16.
You may submit a request or appeal at legal@telltell.co. We verify requests using information associated with you and may request additional information when reasonably necessary. An authorized agent may submit a request with proof of authority. If TellTell processes information only for your organization, we may direct you to that organization and assist it as required by our DPA.
11. Security
TellTell uses administrative, technical, and organizational safeguards designed to protect information, including encryption in transit, cloud access controls, restricted service identities, private storage, conservative logging, and security maintenance. No system can guarantee absolute security. If a qualifying breach occurs, we will provide notices as required by applicable law.
You are responsible for securing the third-party authentication provider account and devices used to access TellTell. TellTell staff will not ask for your identity-provider password. Information included in group email is visible to recipients and may be forwarded or used by them.
12. International privacy principles
TellTell follows the privacy principles of notice, choice, onward transfer, security, data integrity, access, and enforcement reflected in the EU-U.S. and Swiss-U.S. privacy frameworks. TellTell is not currently self-certified under the EU-U.S. Data Privacy Framework, the Swiss-U.S. Data Privacy Framework, or their former Privacy Shield programs.
13. Legal requirements and policy enforcement
We may preserve or disclose information when we reasonably believe it is necessary to comply with law or valid legal process; protect users, TellTell, or the public; investigate fraud, abuse, or security incidents; enforce our Terms; or complete a corporate transaction. We seek to limit disclosures to what is appropriate and provide notice when legally permitted.
Privacy concerns are subject to the dispute provisions in our Terms of Use, without limiting rights to contact a regulator or exercise privacy rights that cannot be waived.
14. Contact and requests
Questions, complaints, privacy-rights requests, appeals, security concerns, and requests concerning your information may be sent to legal@telltell.co. TellTell is subject to the investigatory and enforcement powers of the U.S. Federal Trade Commission and applicable state regulators.
TellTell LLC