Privacy Policy
Effective: July 7, 2026
Tailzu (also referred to as "we", "our", "us") builds a voice-and-text keyboard that transcribes your speech, refines your writing, and helps you communicate. This Privacy Policy explains what personal information we collect through the Tailzu iOS and Android apps and keyboard extension, how we use it, and the choices you have.
By using Tailzu, you agree to this Privacy Policy. If you do not agree, please do not use the app.
1. Information we collect
1.1 Account information
- Email address (when you sign in with email or Apple ID)
- Phone number (only if you choose phone sign-in)
- Name (only if you provide it during onboarding or your Apple ID shares it)
- Language preference and other in-app settings
1.2 Voice and text you send to Tailzu
When you use voice input or the refinement feature, we transmit the audio or text you dictate to our servers and to the AI providers listed below in Section 3 for the purpose of transcription and refinement.
- Voice recordings are processed transiently — sent to a speech-to-text provider, converted to text, and then discarded. We do not permanently store raw audio unless you specifically enable session history in Settings.
- Text you dictate or refine is used to produce refined output and, if you opt in to session history, saved so you can review it later.
- Personality preferences (tone, vocabulary, personal dictionary) are stored so refinement can match your voice.
1.3 Purchase information
If you purchase a subscription, our payment processor (RevenueCat, backed by the Apple App Store or Google Play) provides us a receipt confirming the purchase and its entitlements. We do not receive or store your credit card number.
1.4 Device and diagnostic information
- Device model, OS version, app version, language, timezone
- Push notification tokens (via Apple Push Notification service / Firebase Cloud Messaging) — used to deliver notifications you have opted into
- Advertising identifier (IDFA on iOS) — accessed only if you tap "Allow" on the App Tracking Transparency prompt. Never collected without your explicit opt-in.
- Crash reports and error logs (via Sentry, only if enabled) — used to diagnose and fix bugs
- Usage events (via PostHog, only if enabled) — anonymous aggregate metrics about which features are used, to guide product improvements
1.5 Data you may choose to share via device permissions
The app requests OS-level permissions only when you activate a specific feature. If you deny a permission, the related feature is unavailable but the rest of the app functions normally.
- Microphone — required for voice input. Audio is transient and never stored (see 1.2 above). Flow Sessions: when you start a Flow session, the microphone stays active in the background — iOS shows the recording indicator the entire time — so you can dictate directly from the Tailzu keyboard without reopening the app. The session ends automatically after a period of inactivity (about 10 minutes by default) and you can end it at any time from Settings → End Flow session. Outside of an active Flow session or an explicit dictation, the microphone is off.
- Photos / Photo Library — accessed only when you attach an image to a message or import media. We never scan your library in the background.
- Camera — accessed only when you actively invoke camera capture or QR scan.
- Contacts — accessed only when you tag or mention a contact. We do not upload your contact book to our servers.
- Calendar — accessed only when you dictate an event to add to your calendar.
- Location (precise or approximate) — accessed only if you dictate a location-tagged note or check-in. Not collected in the background.
- Face ID / Touch ID / biometric authentication — used locally on your device to unlock private drafts. Biometric data never leaves your device.
- Clipboard — read only when you paste into the app. We never read the clipboard in the background.
- Bluetooth — used to connect to headsets you pair for voice input.
- Local network — used only if you enable device-to-device sync.
- Speech recognition — on-device recognition; audio processed locally by iOS.
1.6 Non-collection notice
- We do NOT collect your typing outside of when you actively invoke the mic or refine actions.
- The keyboard extension respects Apple's and Google's sandboxing — we do not read passwords, PINs, or content from secure text fields.
- We do not sell personal information to third parties.
- We do not share your content with third parties for their independent marketing.
- We do not use your data to train third-party AI models.
- CCPA notice: in the preceding 12 months we have NOT sold or shared any category of personal information for value.
2. How we use your information
- To provide the core features (transcription, refinement, keyboard, personality)
- To authenticate your account and secure your data
- To process subscriptions and manage entitlements
- To improve the app through anonymous, aggregated usage analytics
- To diagnose and fix crashes and bugs
- To comply with legal obligations
3. Third parties we use
Tailzu depends on the following processors to deliver the service. Each has its own privacy policy.
Speech-to-text
- OpenAI (openai.com/policies/privacy-policy) — processes voice for transcription. Voice is transient and not retained.
- Groq (groq.com/privacy-policy) — alternative transcription provider.
Language refinement
- OpenAI (openai.com/policies/privacy-policy) — refinement, tone matching. Content is transient and not used to train models under our data-processing agreement.
- OpenRouter (openrouter.ai/privacy) — routing layer for language models.
- Anthropic (anthropic.com/legal/privacy) — used through OpenRouter for premium refinement.
Authentication and database
- Supabase (supabase.com/privacy) — hosts your account, profile, and (if opted in) session history in secure managed Postgres.
- Apple Sign In / Google Sign In — used only if you choose these methods; each provider shares only the fields you authorize.
Purchases
- RevenueCat (revenuecat.com/privacy) — manages subscriptions.
- Apple App Store / Google Play — process the actual payment.
Diagnostics (optional)
- Sentry (sentry.io/privacy) — crash and error reporting.
- PostHog (posthog.com/privacy) — anonymous product analytics.
These processors receive only the minimum information needed for their specific function.
4. Data retention
- Voice recordings: transient. Deleted immediately after transcription.
- Session history: only if you opt in. Stored until you delete it or your account.
- Account: retained until you request deletion.
- Diagnostic logs: retained by Sentry / PostHog for up to 90 days per their standard retention.
5. Your rights
Depending on your region (GDPR, CCPA, and similar laws), you have the right to:
- Access — request a copy of the personal information we hold about you
- Correct inaccurate or incomplete information
- Delete your account and associated data ("right to erasure")
- Portability — export your data in a machine-readable format
- Restrict processing in specific circumstances
- Object to processing based on legitimate interests
- Withdraw consent for optional processing (crash reporting, analytics, tracking) at any time
- Non-discrimination — we will not deny service, charge different prices, or provide a different level of service because you exercised any right (CCPA)
- Automated decision-making — request human review of significant decisions made about you by automated systems. We do not currently make such decisions.
- Authorized agent — you may designate an authorized agent to make requests on your behalf (CCPA)
- Complaint — lodge a complaint with your local data protection supervisory authority if you believe we have not complied with applicable law (GDPR)
To exercise any of these rights, contact us at privacy@tailzu.space. We respond within 30 days (45 for CCPA requests, with a possible 45-day extension where permitted). We may request information to verify your identity before processing.
6. Data security
- All communication with Tailzu servers uses TLS (HTTPS).
- Data at rest is encrypted by our infrastructure providers.
- Access to personal data is restricted to necessary personnel.
- We follow industry-standard security practices, but no service can guarantee absolute security.
7. Children
Tailzu is not directed at children under 13. We do not knowingly collect personal information from anyone under 13. If we learn we have, we will delete it.
8. International data transfers
Tailzu is operated globally. Data may be processed in the United States and other countries where our providers operate. Where required by law (GDPR), we rely on Standard Contractual Clauses.
9. Keyboard extension privacy
The Tailzu keyboard extension is a separate iOS/Android app extension with restricted sandboxing:
- The keyboard only sends data to our servers when you explicitly invoke voice or refine actions.
- Normal typing stays on-device and is never transmitted.
- The keyboard cannot see content from secure text fields (passwords, PINs).
- Full Access is only required for voice + refinement features that need network. Without Full Access, the keyboard still functions for regular typing.
10. Changes to this policy
We will update this policy when our practices change. We will bump the "Effective" date at the top and, for material changes, notify you in the app or by email.
11. Contact
Questions or requests: privacy@tailzu.space
This policy is available at https://tailzu.space/privacy. The version served by the app matches the version linked in App Store Connect.