TellAcross was designed from day one with a simple rule: we should never hold data we don't need. Your audio is never recorded. Your calls are never logged.
Six commitments we make to every TellAcross user.
Your voice audio is streamed, processed in real time, and discarded. We don't record calls. We don't keep audio files. There is nothing to breach because there is nothing stored.
All audio, transcript data, and API communication is encrypted using TLS 1.3. Nothing travels in plain text between your browser and our servers.
Camera video streams directly between participants over WebRTC, encrypted with DTLS-SRTP. When a relay is needed it only forwards already-encrypted packets — your video is never decrypted on our servers.
Each call room is a separate session. Participants in one room cannot see, hear, or interact with any other room — even if they share the same account.
Room creation requires an authenticated account. JWT tokens are short-lived and rotated automatically. Guest participants are scoped only to the specific room they were invited to.
Live translations appear during your call and are not written to our database. Saved transcript history is a planned opt-in feature for Pro and Enterprise; until you explicitly enable it, nothing is retained.
If you enable voice cloning, a short sample of your voice is stored to recreate your tone during calls. It is used only for your translated audio, never shared, and removed when you delete your account or voice profile.
We process data in accordance with GDPR principles. Data subjects can request deletion of their account and associated data at any time. We do not sell user data.
A clear picture of how your audio moves through the system — and what happens at each step.
Audio is captured by your browser's microphone. It leaves your device encrypted and streams to TellAcross servers in real time.
Your audio is transcribed in real time using specialist AI speech providers acting as our data processors under data-processing agreements. It is processed in motion — nothing is queued or written to disk on our side — and discarded the moment transcription is complete.
The transcribed text is translated by our AI translation provider, again as a contracted data processor. The result exists only long enough to be turned into speech and delivered — no intermediate state is persisted on our servers.
The translated output is streamed directly to the other person in the call. It is not stored on our servers. It is not logged. It travels encrypted and is played once.
When the call ends, all in-memory session data is cleared. Nothing from the call content persists — only anonymous usage metadata (such as call length) needed for billing.
What we support today, and what we're working toward.
We process EU personal data in accordance with GDPR. Data subject rights (access, deletion, portability) are supported. DPA available on request.
We collect only what is strictly necessary to provide the service. No behavioural tracking, no advertising data collection, no data brokering.
Formal audit underway. Enterprise customers with SOC 2 requirements should contact sales — we can provide our current controls documentation.
Healthcare customers interested in HIPAA-compliant deployment should contact our enterprise team. BAA available for qualified enterprise accounts.
Found a vulnerability? Have a compliance question? Need a DPA or controls documentation for your procurement team?