Privacy Policy
Last updated: September 23, 2026
Tallē ("we", "our", "us") makes connected Docs, Tasks, and Forms apps and web services for iPhone, iPad, and Mac. This policy explains what data we collect, why, and how to control it. We don't sell your data, we don't track you across apps or websites, and we don't use third-party advertising.
1. Information we collect
Account information. When you create an account, we collect your email address, your chosen username, and your display name. If you sign in with Apple, Apple may share a private relay email instead of your real one — we treat both equivalently.
Profile photo (optional). If you upload a profile photo, we store it on your behalf so it's available across your devices.
Content you create. Documents, sermons, journal entries, meetings, Bible bookmarks, folders, task groups, comments, reactions, and any media (such as header, gallery, profile, or post images) you add. Some content can remain only on your device. When you enable cloud features, publish or share content, or use a feature that requires delivery to another person, the relevant content is associated with your account and sent to our service.
Forms and response information. Form owners may store form templates, questions, settings, logos, public share addresses, submissions, and response metadata. A respondent may provide answers, typed or drawn signatures, supported files or links, and optional identifying details such as a name or email address. A submitted response is delivered to the form owner and to collaborators the owner authorizes. Form owners are responsible for what they ask respondents to provide, having an appropriate basis to collect it, limiting access, and deleting or exporting it when it is no longer needed.
Microphone audio (Interpreter Mode only). When you enable Live Interpreter Mode, your microphone audio is processed for speech recognition. Audio is processed on-device when possible and otherwise sent to Apple's speech recognition service. Tallē does not record, store, or transmit your sermon audio to our servers.
Contacts and calendar (optional). Tallē uses Apple's system contact picker and does not request direct access to your full address book. The picker gives Tallē only the contact you choose. A selected or manually entered name, email address, or phone number may be saved with a synced meeting, saved person, or invitation and sent to Firebase or a delivery provider as needed. Tallē requests calendar access only when you choose a calendar action. Calendar entries are read or written on your device for that feature; details you choose to copy or save as Tallē meeting content may sync with that content. We do not upload your address book or calendar wholesale.
Photo library (optional). If you grant permission, Tallē can read images you select and can save shared images to your library. An image you choose for a profile, cover, gallery, post, synced document, or published item may be uploaded so that feature works across devices or for the people with whom you share it. Tallē does not upload the rest of your photo library.
Subscription and billing information. Apple processes purchases made through the App Store. RevenueCat validates purchases and stores entitlement information tied to your Tallē account or installation, and may facilitate web subscription access. Stripe processes card details, invoices, and related billing information for supported web purchases. Tallē receives subscription, product, transaction, and entitlement status needed to provide paid features, but we do not receive your full payment-card number. Website checkout uses your signed-in Tallē account identifier to connect a purchase to your account and checks your current subscriptions before opening checkout.
Website sign-in protection. Our checkout sign-in page uses Firebase App Check and Google reCAPTCHA to help prevent abuse. Google may process browser, device, and interaction information for this security check. Website sign-in is stored for your browser session; sign out before leaving a shared computer. Google's Privacy Policy and Terms of Service apply to reCAPTCHA.
Notifications and installation information. If you allow push notifications and sign in, Tallē stores a Firebase/APNs notification token for that app installation along with a randomly generated installation identifier, platform, app identifier, and last-updated time. We use this information only to route notifications to your devices and remove it when it is no longer needed.
Engage messaging information. If you use Engage, we collect the organization name and role information you provide, phone numbers and contacts you add, audience tags, message drafts, approved outbound messages, scheduled sends, inbound replies, STOP/HELP/opt-out status, delivery events, plan, text usage, free-reply and top-up records, and audit logs needed to operate and document the messaging service.
AI generation inputs. If you ask Tallē to generate message suggestions, we may process the document excerpt, form title, task details, prompt, tone choice, and related context needed to create the draft. You choose whether to approve, edit, or discard the generated text before sending.
Diagnostic and request information. Apple may provide crash and error signals according to your device settings. Firebase, Cloudflare, and other infrastructure providers also process ordinary service-request information such as IP address, browser or device type, timestamps, requested URLs, and security or error logs to deliver, protect, and troubleshoot Tallē. When you are signed in, Tallē may attach your Tallē account identifier to a crash report so we can investigate account-specific failures. We do not currently use third-party advertising identifiers or cross-app tracking.
2. How we use your information
- To run the service: store your documents, sync them across devices, deliver real-time updates within task groups you join.
- To authenticate you: verify it's you when you sign in, support password reset, and link Apple Sign-In.
- To enable subscription features: verify purchases and subscription status with Apple, RevenueCat, or Stripe, depending on where you subscribed.
- To send notifications: route account, collaboration, meeting, and task notices to the app installations where you enabled them.
- To operate Engage: provision and manage text numbers, send and receive text messages, process delivery status, track plan texts, top-ups and free-reply allowances, honor STOP/HELP replies, and keep compliance/audit records.
- To assist with drafting: generate optional AI message suggestions when you request them.
- To improve reliability: diagnose crashes and stability issues from diagnostic data, including crash reports that may be linked to your Tallē account identifier while you are signed in.
3. Who we share your information with
People you choose to interact with. Content you publish, share, assign, or submit is available to the people or organizations you select for that feature. In particular, a form response is shared with the form owner and collaborators the owner authorizes. A recipient may independently export, download, or copy information you share with them.
We share data only with service providers we need to run Tallē, and only the data they need to do their job:
- Google Firebase — authentication, document storage, real-time sync. Data is stored in Google's infrastructure under our project. Firebase privacy.
- Apple — speech recognition, Sign in with Apple, in-app purchases, push notifications. Apple privacy.
- RevenueCat — subscription management. Receives your user ID and subscription receipts. RevenueCat privacy.
- Stripe — card processing, billing, invoices, and subscription management for supported web purchases. Stripe privacy.
- Cloudflare — website delivery, network security, and request processing for talle.app. Cloudflare privacy.
- Telnyx — SMS/MMS messaging, phone number provisioning, delivery status, and inbound replies for Engage.
- AI model providers — optional message drafting. They receive only the content needed for the generation you request.
- API.Bible — Bible verse lookups. We send Bible references; we do not send your account information or document content.
We do not sell your data, share it with advertisers, or transfer it to data brokers.
SMS/text consent. Mobile information — including the phone numbers and SMS opt-in consent that a recipient provides to a church or organization through Engage — is never sold, and is never shared with third parties or affiliates for their own marketing or promotional purposes. Such opt-in and consent information is shared only with the service providers strictly required to deliver the messages the recipient requested (for example, Telnyx, our messaging carrier), and never for any other purpose. All the above categories exclude text-messaging originator opt-in data and consent, which is not shared with any third parties.
4. Where your data is stored
Content you keep local is stored on your device and may also exist in device or computer backups controlled by you and your backup provider. Content you sync, publish, share, or send through Tallē is stored or processed by Google Firebase and the other providers described above. Our primary cloud infrastructure is located in the United States, so cloud data may be stored and processed there and in other locations used by those providers.
5. How long we keep your data
We retain your account and cloud content for as long as your account is active or as needed to provide the Service. When you schedule account deletion from inside the app:
- You are signed out, your account enters a 30-day recovery period, and your owned cloud content and public shares are hidden from ordinary access.
- You have 30 days to recover your account by signing back in and choosing to restore it. The recovery deadline is not extended by repeated deletion requests.
- After the recovery deadline, an automated process permanently deletes your authentication account, owned cloud content, public shares, and stored media covered by the deletion process.
- Limited records in content shared with other people may remain where needed to preserve their task or conversation history, but Tallē removes or replaces account identifiers, profile details, reaction links, and similar authorship fields with an anonymous “Deleted User” identity. Content another person independently copied, quoted, downloaded, or exported is controlled by that person.
- Form responses remain available to the form owner and authorized collaborators until the owner deletes the response or form, or until another applicable deletion process removes it. Copies a form owner or collaborator exported, downloaded, or independently recorded are controlled by that person.
- Engage opt-out records, delivery logs, texting usage and top-up records, billing records, security records, and audit records may be retained as needed to honor recipient preferences, prevent abuse, resolve billing questions, meet carrier requirements, establish or defend legal claims, or comply with law.
- Deleting your Tallē cloud account does not automatically erase local files or copies in device, computer, or third-party backups. You control those copies through the applicable device and backup provider.
- Diagnostic logs may be retained in aggregate, anonymized form.
For step-by-step instructions and subscription reminders, see Delete your Tallē account.
6. Your rights
You have the right to:
- Access the personal information we hold about you.
- Correct inaccurate information by editing your profile in the app.
- Delete your account from Account → Profile → Delete account, subject to the recovery and limited-retention details above.
- Export a structured JSON copy from Account → Profile → Download my data. The export combines supported cloud records with supported local records available to that installation. It does not package binary media or attachment files, content held only on another device, device backups, or copies controlled by another user. If a cloud source cannot be fetched, Tallē still creates the available export and lists the omitted source in the file's
errorssection. - Object to certain processing or withdraw consent for optional permissions (microphone, contacts, calendar, photos) at any time via your device's Settings.
- Opt out of Engage texts by replying STOP to supported messages or contacting the sending organization or Tallē support.
If you're in the European Economic Area, the United Kingdom, or California, additional rights may apply under GDPR / UK GDPR / CCPA. To exercise any rights or ask questions about how your data is processed, contact us at the address below.
7. Children's privacy
Tallē is not directed at children under 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, please contact us and we'll delete it.
8. Security
We use industry-standard practices: encrypted transport (HTTPS), encrypted-at-rest storage in Firebase, server-side access control rules that prevent users from reading each other's content, and required reauthentication for sensitive actions like account deletion. No system is perfectly secure, but we take reasonable steps to protect your information.
9. Changes to this policy
We may update this policy as Tallē evolves. When we do, we'll change the "Last updated" date at the top and, for material changes, surface a notice in the app. Continued use of Tallē after a change means you accept the updated policy.
10. Contact
Questions, requests, or concerns? Email support@talle.app.