Security & Privacy

Your conversations stay yours.
Full stop.

TellAcross was designed from day one with a simple rule: we should never hold data we don't need. Your audio is never recorded. Your calls are never logged.

How we protect your data

Six commitments we make to every TellAcross user.

Audio is never stored

Your voice audio is streamed, processed in real time, and discarded. We don't record calls. We don't keep audio files. There is nothing to breach because there is nothing stored.

Encrypted in transit

All audio, transcript data, and API communication is encrypted using TLS 1.3. Nothing travels in plain text between your browser and our servers.

Video is peer-to-peer encrypted

Camera video streams directly between participants over WebRTC, encrypted with DTLS-SRTP. When a relay is needed it only forwards already-encrypted packets — your video is never decrypted on our servers.

Rooms are isolated

Each call room is a separate session. Participants in one room cannot see, hear, or interact with any other room — even if they share the same account.

Authentication required

Room creation requires an authenticated account. JWT tokens are short-lived and rotated automatically. Guest participants are scoped only to the specific room they were invited to.

Transcripts are not stored

Live translations appear during your call and are not written to our database. Saved transcript history is a planned opt-in feature for Pro and Enterprise; until you explicitly enable it, nothing is retained.

Voice samples handled with care

If you enable voice cloning, a short sample of your voice is stored to recreate your tone during calls. It is used only for your translated audio, never shared, and removed when you delete your account or voice profile.

GDPR-ready

We process data in accordance with GDPR principles. Data subjects can request deletion of their account and associated data at any time. We do not sell user data.

What happens to your data during a call

A clear picture of how your audio moves through the system — and what happens at each step.

01

You speak

In transit — encrypted

Audio is captured by your browser's microphone. It leaves your device encrypted and streams to TellAcross servers in real time.

02

Voice is processed in real time

Processed live, not stored

Your audio is transcribed in real time using specialist AI speech providers acting as our data processors under data-processing agreements. It is processed in motion — nothing is queued or written to disk on our side — and discarded the moment transcription is complete.

03

Translation is generated

In memory only

The transcribed text is translated by our AI translation provider, again as a contracted data processor. The result exists only long enough to be turned into speech and delivered — no intermediate state is persisted on our servers.

04

Audio is delivered to your participant

Streamed once, not stored

The translated output is streamed directly to the other person in the call. It is not stored on our servers. It is not logged. It travels encrypted and is played once.

05

Session ends

Session cleared

When the call ends, all in-memory session data is cleared. Nothing from the call content persists — only anonymous usage metadata (such as call length) needed for billing.

Compliance & certifications

What we support today, and what we're working toward.

GDPR

Ready

We process EU personal data in accordance with GDPR. Data subject rights (access, deletion, portability) are supported. DPA available on request.

Data minimisation

By design

We collect only what is strictly necessary to provide the service. No behavioural tracking, no advertising data collection, no data brokering.

SOC 2 Type II

In progress

Formal audit underway. Enterprise customers with SOC 2 requirements should contact sales — we can provide our current controls documentation.

HIPAA

On roadmap

Healthcare customers interested in HIPAA-compliant deployment should contact our enterprise team. BAA available for qualified enterprise accounts.

Security questions answered

Can TellAcross employees listen to my calls?+
No. Audio is processed in real time by automated systems and is not accessible to TellAcross staff. There is no playback, no review, and no monitoring of call content.
Where are your servers located?+
TellAcross infrastructure runs on major cloud providers with data centers in the EU and US. Enterprise customers can request region-specific deployment to satisfy data residency requirements.
How are guest participants secured?+
Guests who join via link are scoped only to that specific room and session. They cannot access other rooms, other users' accounts, or any data outside the call they were invited to.
Do you share data with third parties?+
We use third-party AI APIs to process speech and translation in real time. These are data processors acting under our instructions and are bound by their own security and privacy commitments. We do not sell user data to any third party.
What happens to my data if I delete my account?+
Account deletion removes all associated user data, including profile information and any saved transcript history, within 30 days of the deletion request.
Do you have a security vulnerability disclosure process?+
Yes. If you discover a security vulnerability in TellAcross, please contact us at info@tellacross.com. We commit to acknowledging reports within 48 hours and working with you on responsible disclosure.

Security contact

Found a vulnerability? Have a compliance question? Need a DPA or controls documentation for your procurement team?