TellyPrompter

Privacy

Last updated 24 September 2026

TellyPrompter is a teleprompter that runs in your browser. This page says what leaves your device, what does not, and who else is involved. It is written to be read rather than to be defensible.

Who we are

The data controller is TellyPrompter, at beyond Aldgate Tower, 2 Leman St, London E1 8FA. You can reach us at contact@tellyprompter.com.

Using the prompter without an account

You do not need an account to paste a script and read from it. If you never sign in, we hold no account, no email address and no script library. Your scripts, your settings and your script library are stored in your browser's local storage on your own device, and the library itself is not sent to us. One honest caveat: session replay, described below, shows what the app displayed — including a script while it was on the prompter stage — unless you switch usage sharing off.

If you upload a Word, plain text or Markdown file, your browser reads it on your device and extracts the script there. The file itself is not uploaded to us.

Speech recognition, which needs care

Speech recognition does not send audio to TellyPrompter. It uses the speech recognition built into your browser; we do not operate a speech service. A recording reaches our storage only when you choose Save to account. The text the recogniser produces during a take can reach us, if you have an account and have left usage sharing on — that is described plainly under "Improving how the script follows you" below.

That does not always mean the audio stays on your device. Some browsers implement their speech API by sending audio to their own servers — Chrome's is documented as server-based, which is why dictation there does not work offline. Where your browser works that way, your voice reaches your browser vendor under their privacy policy rather than ours, and what they do with it is governed by their terms.

Where a browser can recognise speech on the device itself, we ask it to. Standby listening — the idle listening between takes — is switched on only when the browser has confirmed it can run locally, so an empty room is never streamed to anyone's server while you are not reading.

Audio and video recordings

You can download recordings to your own device. A recording is uploaded to our private Supabase storage only when you sign in and choose Save to account. This stores the original audio or video file and its title, filename, size, duration and optional script reference so you can retrieve it later.

Saved recordings are available to your own account. Playback and download use temporary links that anyone holding the link can use until it expires, after 15 minutes. We keep saved recordings until you delete them in My recordings or delete your account. Deleting a script or clearing local take history does not delete an account recording. After recording deletion, we retain an internal identifier to prevent stale requests from restoring it; its title, filename and script reference are removed.

When you request an account save, the browser also tries to keep a local retry copy until the upload is confirmed. Failed saves can be retried, or their local retry copies removed, from My recordings. These copies stay on that device and are associated with the account that requested the save.

If you choose to keep the recording of a rehearsal as an ear track, it is stored inside your browser's own storage on this device so the app can play it back to you. It is never uploaded to us. It is deleted when you delete the script it belongs to, and when you use Reset everything.

If you create an account

An account supports script syncing, recordings you choose to save, and billing. What we hold is:

What Why How long
Your email address To sign you in, and to contact you about your subscription Until you ask us to delete the account
Whether you have paid, and until when To decide what the app offers you Until you ask us to delete the account
A Stripe customer reference To connect your account to your payments As above, subject to the accounting record below
Recordings you choose to save, and their metadata To let you play and download them on another device Until you delete the recording or your account
How many script suggestions you asked the third-party model for To cap what one account can spend on that model in an hour Until you ask us to delete the account
How the script followed you during takes To improve voice matching for everyone Word traces and the script 90 days; summary numbers until you delete the account; a nightly summary naming the most-missed phrases stays in our issue tracker; an occasional take kept as an anonymised test case has no end date

Scripts, if you have an account

Signing in stores your scripts on our infrastructure so they can sync between devices. That is the point of the feature, and it means the text of those scripts leaves your device. A free account keeps up to five scripts this way; Pro keeps as many as you write. Without an account nothing is synced at all, and your scripts never leave local storage.

Synced scripts are held in a database in Ireland (EU), readable only by your own signed-in account, enforced in the database rather than in the app. Deleting a script marks it deleted so the deletion reaches your other devices. You can download every script you have, at any time, on any plan, from the Export button in your library — no account required.

A hand-off link you create for an editor stores that take's script text, its word timings and your review decisions on our servers until the link expires or you revoke it, and never audio or video; anyone with the link can read that take without an account.

Suggestions while you prepare a script

If you are signed in, text from the script you are preparing is sent to a third-party model, and what comes back is shown as a suggestion. This happens at six moments in the composer: when you paste or import a script, when you open Readiness, when you open Record in sections, when you open Production cues, when the language is on Auto-detect and the detector cannot decide, and when you compare lines under Different openings and endings. While one of those panels stays open, the asking continues: each time you change the text and pause, the changed text is sent again, so words you type after opening a panel go too. At each of those moments TellyPrompter asks a model run by TypeSafe AI, Inc. a handful of small questions about the text — is this line a stage direction rather than speech, is this warning worth showing, does a section break belong here, which language is this opening written in, how does this line rate for spoken delivery — and paints the answers as suggestions. Nothing is changed in your script until you accept one, with one exception that changes no words: when Readiness has been judged, the model's reading of each number in the script — a year, a quantity, a phone number — is kept with that script and shapes which spoken forms the prompter listens for during a take, so that "2024" is heard as "twenty twenty-four" rather than "two thousand and twenty-four". When no answer comes back, because you are offline or the model is busy, the composer behaves exactly as it would without the feature.

What is sent is text you wrote and nothing else: the script or the lines the question is about, the opening of the script for the language check, a word with its sentence for a pronunciation cue. Never audio, never video, never the words the recogniser heard during a take, and never your email address, your name or any account detail. The request travels from a server we run to TypeSafe's service, which is hosted in the United States. TypeSafe states in its privacy policy that it does not train or fine-tune models on what is sent to it, and in its data processing agreement that it keeps what it receives for as long as necessary to provide the service; it names no fixed period, so we do not promise one. What we keep ourselves is a count and no text: which account asked, when, and how many questions, so that one account cannot run up the bill. That count is deleted with your account.

Without an account nothing is sent, because these suggestions only work while you are signed in, and the Ear Prompter app for iPhone and iPad does not ask at all. The Share usage data switch does not reach this: it governs the matching reports and analytics described elsewhere on this page, not these requests, the words they carry to TypeSafe, or the count of them we keep, and there is no separate switch for those yet. If you would rather no script of yours reached TypeSafe, prepare it signed out, which keeps every other feature of the composer.

Improving how the script follows you

When you finish a take with an account signed in, TellyPrompter sends itself a report of how well the script kept up with your voice: counts of matched, corrected and missed words, and a trace of the matching decisions — including the words the browser's speech recognition heard during that take, and the script you were reading, so that take can be replayed exactly as it happened. We use these reports for one thing: finding the deliveries the matcher fumbles and fixing them, so the script follows everyone a little better with each release.

Plainly, because it matters: a trace contains recognised speech from your take. It is not audio — no recording exists for us to receive — but it is the words the engine transcribed while you read your script. Traces are deleted automatically after 90 days, and the script travels with the trace under exactly those rules: ninety days, gone the moment you delete that script, gone with the account. The numbers-only summaries identify no words and are kept with the account. Each night a summary of the previous day's matching is carried by n8n Cloud, the scheduler we run it on, to Linear, the issue tracker we plan the matcher's fixes in: the counts, and the handful of phrases the recogniser most often failed to place, taken from traces and attributed to no person and to no script. n8n holds the summary only while it passes it on; Linear keeps that comment as part of the tracker's history.

Takes guided by an ear track report like any other, marked as guided. On those takes the recogniser can hear your own rehearsal recording playing back as well as your live read, so a trace may include its transcription of that playback. On guided takes we also record what the ear track did and when: each time it held, resumed or moved, by script position, together with the ear settings in force — the lead you chose and the volume you set it to. That part is not speech and names nothing you said; it is how we tell a guide voice that paused because you did from one that paused because the script lost you. The audio itself still never reaches us — the ear track stays in your browser's storage, as described under video recording above.

Now and then one take teaches us more than a month of summaries — a stretch where the script plainly lost its reader. A take we find instructive may be kept as a test case for longer than 90 days. When that happens it is copied into a separate collection and cut loose from you first: the copy carries no account, no email, no name and no script identity — only the words, the script and what the matcher made of them. It is not deleted after 90 days and it is not deleted with your account. That is the point of cutting it loose: once the original take is gone, nothing left anywhere links the copy back to you. If you would rather no take of yours were ever kept this way, switch off Share usage data and none ever will.

This is on by default, and yours to refuse: switch off Share usage data in Settings and nothing is sent at all, with no change to how the prompter works. Without an account no matching report is ever sent, because there is nowhere to file it. Deleting a script deletes its traces at the same moment; deleting your account deletes every report of yours.

Google Docs import

If you import a Google Doc, the document is fetched through a small service we run on Cloudflare, which passes it to your browser. We do not store the document or its address. This works only for documents you have shared publicly with a link, and the request reaches Google as well as Cloudflare.

Product analytics

We collect product analytics: which screens and features are used, which site or link sent you here including any campaign tags in the address, broad technical information such as browser, operating system, device type and country, and a replay of the app's own screens.

Words from your script can reach it too. A replay shows the stage while you read, and the text of whatever you click is recorded, which in the composer or your library can be your own words rather than ours. A finished take carries a short one-way code derived from your script, which says which script was read without containing any of it and cannot be turned back into words, together with the language the recognition ran in. Your audio and video recordings are never part of any of it. We would rather say all this than promise a masking that does not hold.

It is not anonymous. An identifier is stored in your browser so that a visit which starts on the home page and carries on into the prompter is counted once rather than twice, and if you are signed in that identifier is linked to your account. It is collected for us by third-party analytics providers rather than held only on our own servers. The Share usage data switch in Settings turns off everything the app collects about how you use it; it does not reach the home page, where analytics run whatever the switch says, and it does not reach the script suggestions described above, which keep sending text to TypeSafe and keep their count of requests whatever the switch says.

Replays are kept for 30 days, though a random sample of them, any we choose to keep, and the heat-map summaries drawn from them can be held for up to nine months. The event records — which screen, which feature, when — are kept for seven years. Deleting your account does not delete any of it: what is already linked to your account stays until it expires on that schedule, unless you ask us to erase it sooner, at the address under Your rights.

Affiliate referral attribution

Every page loads a script from Refindie so we can attribute referred visits and purchases to an affiliate. When you arrive through a link containing a referral code, Refindie receives that code, our site domain, your browser's user-agent and the IP address needed to answer the request. It sets a first-party cookie named refindie_ref_319 for the attribution period configured in our affiliate programme. The cookie contains the referral code; it does not contain your scripts, recordings, audio or account details.

We do not use Refindie for advertising or to record how you use the prompter. Visitors without a referral code still download the Refindie script, but it does not create the referral cookie or record an affiliate visit for them.

Ear Prompter for iPhone and iPad

Ear Prompter is the same product as a native app for iPhone and iPad. Most of this page applies to it as written; this section says where the app differs, and it differs mostly by sending less.

Scripts stay on the device. The app keeps your scripts, drafts and settings in its own storage on the phone or tablet. Nothing syncs to your account yet, even when you are signed in, so the text of a script never leaves the device unless you share it yourself from the script's page.

Speech recognition runs on the device. The app uses Apple's on-device speech recognition to follow where you are in the script. Your voice is not sent to us and not sent to Apple for recognition; the one thing downloaded is a language pack, from Apple, when you choose a language the device does not yet have. There is no server fallback: if the device cannot recognise a language, the app says so rather than sending audio anywhere.

Reads and takes never upload. The rehearsal read that plays in your ear, and the audio or video takes you record, are stored inside the app on that device, protected by the device's own encryption. They leave it only when you press Share, Save to Files or Save to Photos, and then only to where you send them. Deleting a script deletes its reads; takes stay until you delete them in the app. There is no cloud copy, so there is nothing of them for us to hold or to delete.

If you sign in. You can sign in with Apple, with Google or with a code sent to your email. With Sign in with Apple you can hide your address, in which case what we hold is Apple's relay address for you. We hold the address and an account identifier, in the same database in Ireland described above, and nothing else about you; the app does not ask for your name. You can delete the account from inside the app, under You, and that removes the address, the account, and every matching report of yours at the same time.

Improving how the script follows you, without the words. When you finish a take signed in, with Share usage data on, the app sends a report of how the read kept up with you: counts of matched, corrected and missed words, and where in the script the ear track held, resumed or moved, as positions and timings. Unlike the browser app, this report carries no recognised speech and no text of the script. The words are never in it, so there is nothing to keep as a test case; the numbers are kept with the account and deleted with it.

Product analytics. The app records which screens and steps are used, on the same terms and with the same analytics provider as the web app, in the EU, and never a replay of the screen: there is no session replay in the app. Events carry a random identifier the app makes up when it is installed, which is not your account and is not your device's advertising or vendor identifier; reinstalling the app starts a new one. Words from a script, your recordings and your voice are never part of it. The Share usage data switch under You turns all of it off, and it is on by default as it is on the web.

Crashes and diagnostics. If the app crashes and you have allowed Apple to share analytics with developers, Apple sends us a crash report on Apple's terms. The app also keeps a diagnostics log on the device, of timings, counts and settings, never words; it leaves the device only when you press Share evidence under Diagnostics and choose where it goes.

Nothing to buy yet. The app has no purchases and no subscription, so it collects no purchase information. If that changes, this section will say what is collected before it is.

Your rights

You can ask us for a copy of what we hold, ask us to correct it, or ask us to delete it. Write to contact@tellyprompter.com and we will act within a month. You can also complain to the Information Commissioner's Office at ico.org.uk.

Deleting your account removes your email address, your entitlement record, your synced scripts, your count of script-suggestion requests and every matching report, traces and numbers alike. It does not remove the product analytics described above, which expire on their own schedule unless you ask us to erase them. Records we have to keep for tax and accounting are kept for as long as the law requires, and no longer.

Home Terms Refunds Accessibility Open the app