Telbox Privacy Policy
Last updated: July 22, 2026 · Version: 3.3
This policy describes what data Telbox collects, how we use it, who we share it with, how long we keep it, and what choices you have. It is written for end users (you) and to be read by regulators. If anything in here is unclear, write to privacy@telbox.ai and we will answer.
A summary of the most important things first:
- Transport encryption is always on, on every tier. Every message, voice note, and call you send through Telbox travels end-to-end encrypted between your device and the recipient's device. Telbox itself cannot read your messages while they are in transit. This is true for Free, Plus, Pro, Business, and Workforce users alike.
- When AI features are on, we decrypt your content on our servers to process it. AI features cannot run on ciphertext. When AI is on for a conversation, the relevant message or voice note is decrypted inside our AI worker, processed, and the in-memory plaintext is discarded. "We never see your content" is not true when AI is on. Turn AI off (per conversation or entirely) and nothing is decrypted for AI — it stays end-to-end encrypted.
- AI processing is no-training on every tier. When AI runs, content is sent to our AI processor under a paid commercial contract whose terms prohibit using your content to train models. The processor and its no-training terms are the same on every tier: Free, Plus, Pro, Business, and Workforce differ in usage limits, never in AI privacy posture. Our AI sub-processor is identified in the sub-processor list (§3.6).
- You can turn AI off at any time. Switch it off for a single conversation or for your whole account in Settings, wipe what the AI has remembered in one tap, or delete your account.
0. Reading guide
This policy is intentionally long because we describe the AI processing path in unusual engineering detail and the legal posture varies by jurisdiction. Section 3 ("How AI processes your content") is the load-bearing section — read it before using AI features. Section 7 ("Your rights") spells out what you can request and how. The remaining sections are reference material.
If you only have time for the headline: transport is always end-to-end encrypted; when AI is on we decrypt on our servers to process (no-training on every tier); AI is on from the start and you can turn it off — per conversation or entirely — at any time.
1. Who we are
Telbox AI Labs LTD is a company registered in England and Wales, United Kingdom. Telbox AI Labs LTD is the data controller for the personal data we process about end-user consumer accounts (Free / Plus / Pro). For Business and Workforce tenants, Telbox AI Labs LTD is the data processor acting on behalf of the customer organization that holds the tenant subscription.
Contact:
- General: hello@telbox.ai
- Privacy: privacy@telbox.ai
- Mailing: Telbox AI Labs LTD, 128 City Road, London EC1V 2NX, United Kingdom.
2. What we collect, per tier
The categories below describe what Telbox stores on our servers. Material on your device (the iOS app's local SQLite cache, iCloud Keychain entries, etc.) is governed by Apple's terms and is outside the scope of what we "process" in the privacy-law sense.
2.1 Identity + account
- Display name, email or phone number (whichever you used to sign up), and per-device cryptographic identity keys.
- Profile photo if you upload one.
- iCloud-Keychain-synced long-lived identity public key (the private half stays on your device).
We use these to authenticate you, route messages, and verify device-to-device trust relationships.
2.2 Messages and media
- Each message is stored as ciphertext that we cannot read. The encryption envelope is sealed independently to each recipient device using X25519 key exchange + AES-256-GCM authenticated encryption. The same envelope shape applies to text, voice notes, photos, video, and file attachments.
- A per-recipient sealed key envelope is stored alongside the ciphertext. Only the intended recipient device's private key can unwrap the envelope.
- Metadata we do see: thread membership, message timestamp, message size, sender and recipient user IDs, recipient device IDs, message type (text / voice / image / ...), and — because our servers relay them in real time so your conversations feel live — presence / online status, last-seen, typing indicators, and delivery + read receipts. Of these, we store your last-seen time and your delivery and read receipts (so a message can show "delivered" or "read" and so a contact can see when you were last active); typing indicators and presence / online status are transient relay signals we do not retain. We use this metadata to route and deliver messages and drive these live cues, not to profile you, and we never sell it.
2.3 Voice + media blobs
- Encrypted blob storage in Google Cloud Storage. The blob ciphertext is encrypted-at-rest (Google's default GCS encryption) and the contents are encrypted before upload by your device using the same envelope keys as the message.
- We never store voice recordings in any unencrypted form.
2.4 AI-derived data (only when AI is enabled)
When AI is enabled (it is on from the start; you can turn it off at any time), our worker decrypts each message inside our infrastructure and sends the plaintext content to an AI processor. The processor returns a transcript (for voice notes), a summary, extracted tasks, extracted people, and other "understanding" artifacts. These are stored alongside the message in our database.
The AI processor is the same on every tier: a third-party AI processor used as a paid service (billing attached), governed by that provider's commercial terms for paid use. Under those terms the provider does not use your prompts or responses to train its models. There is no Telbox tier whose AI traffic routes to a trainable endpoint. The processor is identified as a sub-processor in §3.6, and changes to that list are announced with 30 days' notice.
2.5 Subscription state
- The Apple StoreKit2 receipt fields for your active subscription: original transaction ID, expires-date timestamp, environment (Sandbox vs Production), product ID, auto-renew status. Stored as a JSONB blob alongside your account.
- The paywall disclosure version you saw when you subscribed (a build-versioned identifier). Used as audit trail for FTC ROSCA disclosure compliance.
- Apple sends us subscription-event notifications (renewal, lapse, refund, family sharing) via the App Store Server Notifications V2 endpoint; we update your account state in response.
2.6 Consent timestamps
We store three timestamps that represent your onboarding consent and notice state:
transport_e2e_acknowledged_at— when you acknowledged the transport-E2E information screen.ai_processing_consent_at— when AI-processing consent was recorded for your account. AI features are on from the start, so for new accounts this is recorded at account creation; turning AI off in Settings stops all AI processing regardless of this timestamp.ai_training_consent_at— a legacy timestamp from the retired (pre-2026-05-19) free-tier training disclosure. Kept for audit history only; it no longer affects how any content is processed or routed.
These are the audit trail of your consent and notice state.
2.7 Device push tokens
If you grant iOS notification permission, we store the APNs token issued by Apple. We use it to send you alerts when something happens (new message, call invite, subscription lapsed). We never include the plaintext of your messages in a push payload — the body is the AI-generated summary if available, otherwise a generic placeholder like "Voice note" or "New message."
2.8 Audit log
Limited record of administrative events: account creation, device registration, device revocation, subscription state changes, AI consent state changes, deletion requests, legal-process responses (subpoenas, takedown notices). Stored separately from user content for legal-hold + abuse-prevention purposes.
2.9 What we do NOT collect
- We do not embed third-party advertising SDKs.
- We do not embed third-party analytics SDKs that exfiltrate user content.
- We do not collect location data in the background, for advertising, or to profile you. Location leaves your device in exactly two ways, both of which you initiate: (a) a location message you choose to send, which travels end-to-end encrypted like any other message and whose contents we cannot read; and (b) on Android, if you have granted location access for Ask, a coarse recent location attached to an Ask question you submit — see §2.10.
- We do not read your contacts list for advertising, profiling, or social-graph building, and we do not upload it in the background. The in-app "Match contacts" feature hashes your contacts on-device, sends only hashed truncations, and discards the response. Separately, on Android, if you have granted contacts access for Ask, matching contact entries are attached to an Ask question you submit so it can resolve who you mean by name — see §2.10.
- We do not record live video-call media as a continuous stream for later playback. Separately, when post-call AI insights are enabled for a call, participating clients may upload encrypted call-segment audio so our AI worker can produce a summary; those segments are ciphertext at rest and are erased with account deletion (and with "Clear AI memory" for the derived insights). Whether your device uploads any call audio follows your AI settings: with AI (or call insights) turned off, your device captures and uploads no call audio; with them on, your device uploads only your own microphone audio for that summary.
- We do not access your photos library (the share-extension flow only sees what you explicitly tap into Telbox).
2.10 Personal context you attach to Ask (Android)
Android only. The Ask feature can attach personal context from your phone to the question you submit, so it can answer things like "when am I seeing Sarah?". Each source is off until you grant the matching Android permission, and each has its own control in Settings → Privacy:
| Source | What is attached | Permission |
|---|---|---|
| Contacts | Name, phone numbers, email addresses, organisation for matching entries | READ_CONTACTS |
| Calendar | Upcoming events for the next 14 days: title, start/end, location, calendar name | READ_CALENDAR |
| Location | A single coarse recent position (latitude, longitude, accuracy, timestamp) | ACCESS_COARSE_LOCATION |
This context is sent with the Ask request to our servers and decrypted there, exactly like the rest of an AI request (§3.0) — it is not end-to-end encrypted, because the AI cannot read ciphertext. It is used only to answer that question, routed through the same no-training processor as all other AI content (§3.1), and is not retained as a separate contacts, calendar, or location record.
If you do not grant these permissions, nothing from these sources is sent. Revoke any of them in Android Settings at any time and attachment stops immediately. iOS does not attach any of these sources to Ask.
3. How AI processes your content
This section is the load-bearing one. Please read it before you use AI features.
3.0 Plain statement: what "AI on" means for your encryption
This is the single most important thing to understand about Telbox, so we state it plainly and separately:
- Transport is always end-to-end encrypted. Between your device and the recipient's device, and while stored on our servers at rest, your content is ciphertext we cannot read.
- AI processing requires decryption. AI features cannot operate on ciphertext. When AI is enabled for a conversation, our AI worker process decrypts the relevant message or voice note in memory to transcribe, summarise, or answer questions about it. We do not persist that plaintext after processing; what we retain is the AI-derived output (for example, a transcript or summary), described in §2.4 and §6.
- You consent to this decryption when you use AI. AI is on by default for new accounts; using an AI feature is your consent to the server-side decryption-for-processing described here. You can withdraw it at any time by turning AI off for a conversation or entirely (Settings → AI), after which no decryption for AI occurs.
- The processing endpoint never trains on your content. There is exactly one AI-processing endpoint, used as a paid service under a binding no-training contractual term, and it is the same endpoint for every tier (Free, Plus, Pro, Business, Workforce). Paid tiers differ only in usage limits and cost, never in this privacy posture. See §3.1 and §3.6.
If any statement here conflicts with what the app actually does, treat the app's behaviour as authoritative and tell us at privacy@telbox.ai — we will fix the discrepancy.
3.1 Every account routes through the same no-training endpoint
When AI features run — on any tier — your messages and voice notes are decrypted inside our infrastructure and sent to our AI processor, used as a paid service, for processing. Under that provider's commercial terms for paid use, it does not use this content to train its models. There is a single such endpoint — Telbox does not maintain a separate "free/trainable" AI path. Every AI call, on every tier, is decrypted server-side only for the duration of processing and routed to this one no-training endpoint. The processor is identified in the sub-processor list (§3.6).
AI features are on from the start for new accounts. If you do not want AI processing:
1. Turn AI off for a single conversation. Telbox supports per-thread AI-off overrides. 2. Turn AI off entirely in Settings → AI. Nothing leaves your device for AI processing while it is off.
3.2 What paid tiers change
Telbox Plus, Pro, Business, and Workforce change usage limits — monthly AI quotas, priority, and capacity — not the privacy posture. Paid and free AI workloads route through the same no-training endpoint described in §3.1.
3.3 Transport encryption stays in place regardless of tier
Whether you are on free or paid, your messages travel from your device to ours encrypted, and the recipient's device decrypts them. We never see plaintext in transit. What happens after the server-side decrypt inside the AI worker process is also the same on every tier: processing by the no-training endpoint described in §3.1.
3.4 If your subscription lapses
If a Plus / Pro / Business subscription ends and you drop back to the free tier, your usage limits change (the free tier's monthly AI quotas apply again). Your AI privacy posture does not change — free-tier AI calls route to the same no-training endpoint as paid calls.
3.5 When someone else sends you content
Telbox is a messaging app. People send each other content. When you send a message to another Telbox user whose AI is on, the recipient's Telbox account processes your content through AI — for example, transcribing and summarizing your voice note for them. That processing goes through the same no-training endpoint described in §3.1, regardless of the recipient's tier.
By using Telbox to send content to other Telbox users, you consent to this processing. If you prefer that a particular conversation never be AI-processed:
- Ask the recipient to turn off AI for that conversation — Telbox supports per-thread AI-off overrides.
- The conversation's AI posture is visible in its Trust Center, so you can check at a glance who — and which AI — can read the thread.
3.6 Sub-processors
Data-protection law requires us to identify the processors we use, so the entities below are named. The full sub-processor list is at https://telbox.ai/sub-processors and is updated with 30 days' notice when changes happen. Today's list:
- Google LLC (United States) — AI processing, used as a paid service on no-training terms, for all tiers. Subject to that provider's commercial terms for paid API use.
- Google Cloud EMEA Ltd. (Ireland) — infrastructure (Cloud Run, Cloud SQL, Memorystore Redis, Google Cloud Storage). Subject to Google Cloud DPA.
- Apple Inc. (United States) — iOS push notifications via APNs. Subject to Apple's standard service agreement.
- Cloudflare Inc. (United States) — DNS hosting. Subject to Cloudflare's DPA.
- Stripe Inc. (United States) — B2B billing (Workforce tier). Subject to Stripe's DPA.
- Functional Software, Inc. (Sentry, United States) — error tracking. Subject to Sentry's DPA.
3.7 What we never do with your AI workload (regardless of tier)
On every tier, Telbox itself never sells your data, embeds advertising profiles, or uses your messages to target ads — and since 2026-05-19, no Telbox tier routes AI workload to a trainable endpoint: our AI processor is contractually barred from training on any Telbox user's content, free or paid (the processor is named in the §3.6 sub-processor list).
Specifically, regardless of tier:
- Telbox does not target advertisements at you.
- Telbox does not run third-party advertising or analytics SDKs that exfiltrate the contents of your messages. (We use Sentry for crash and error diagnostics, with personal data scrubbed — see the sub-processor list in §3.6.)
- Telbox does not train its own AI models on your content. We do not even keep the ML training datasets that would make that possible.
- Telbox does not sell aggregate, anonymized, or pseudonymized derivatives of your AI-processed data to data brokers.
- Telbox does not allow internal teams to read your messages outside of named two-person reviewed operational support tasks (debugging a crashed message, responding to legal process, processing a deletion request you yourself triggered).
What changes between Free and paid tiers is usage limits, not the privacy contract. All tiers route AI through the same sub-processor (named in §3.6) on the same no-training terms.
3.8 Inspectable architecture
We publish a plain-language, engineering-detail description of these data flows — the end-to-end envelope, the server-side decryption that AI processing requires, the per-user factory that gates and meters your AI workload, and the no-training guarantee — as a public page at https://telbox.ai/architecture/. The factory's read path defaults to FREE when a user record is missing or a tier column is unset — which affects only usage limits; the no-training routing is uniform across tiers. That public page describes the same data flows this policy describes; deeper internal architecture documentation is available to qualified auditors and researchers on request at info@telbox.ai. If you find a contradiction between that page, this policy, and what the app actually does, the document is the bug — tell us at info@telbox.ai and we will fix it.
4. Who we share data with
We share data with the following categories of recipients, on the legal bases noted:
- AI processor. As described in §3; the processor is named in the §3.6 sub-processor list, and sharing is governed by that provider's paid-service terms / DPA.
- Push notification providers (Apple). Push payloads include only the AI summary or a generic placeholder; never raw ciphertext or unencrypted message content.
- Infrastructure providers (Google Cloud). Encrypted blobs and database rows are stored in Google Cloud infrastructure in our chosen region. Workload Identity authentication; no service-account keys.
- Business / Workforce tenants. When you sign up under a B2B tenant subscription, the tenant administrator can see your messages and AI-derived data per the tenant's data-processing agreement. The tenant's privacy policy governs internal access.
- Authorities responding to lawful process. We respond to subpoenas, court orders, and emergency disclosure requests per our published Subpoena Response Procedure. We notify the affected user unless legally prohibited.
- Acquirer. In the event of a corporate transaction (acquisition, merger), data may transfer to the new entity. We will give 30 days' notice in-app before any such transfer.
We do not sell your data to advertisers, data brokers, or any third party.
4.1 What "lawful process" means in practice
Authorities occasionally serve Telbox with a subpoena, court order, search warrant, or emergency disclosure request. Our standing policy:
- We respond only to legal process we determine to be valid under the law of the jurisdiction asserting it. We push back on overbroad requests with the help of counsel.
- Where the requesting jurisdiction's law and the user's resident jurisdiction's law conflict, we route to the user's resident jurisdiction's protections when feasible.
- For requests involving message ciphertext, we can only produce what we hold: encrypted blobs we cannot read. The Apple device key needed to decrypt is in the user's iCloud Keychain on the user's device; we do not have it.
- For requests involving AI-derived data (transcripts, summaries) on accounts where AI is enabled, we can produce the derived data. We log every such production to our Subpoena Register.
- We notify the affected user within 24 hours of receiving the request unless legally prohibited (gag order). If we are prohibited from notifying, we re-evaluate the gag every 90 days and notify the moment we are no longer prohibited.
- Aggregate transparency reports are published at https://telbox.ai/transparency yearly.
4.2 Internal access
A small number of Telbox engineers have administrative access to the production environment. Production-data-touching operations require:
- Named two-person review (one engineer initiates; one engineer approves) for any action that reads user content.
- Audit log entry in the platform-audit table with engineer ID, action, target user, and justification.
- Quarterly access review by the founder.
This applies to manual interventions only (e.g., debugging a crashed AI worker on a specific user's message at the user's explicit request). Routine backend operation (the AI worker, the message router, the API server) operates on encrypted data only and does not constitute "internal access" in this sense.
5. International data transfers
Telbox is built in Dubai (UAE) and the production stack runs on Google Cloud in us-central1 (Iowa, United States). Our AI processors are Google LLC (USA). When you are an EU/EEA/UK or MENA resident, your data transfers to the United States for AI processing.
Telbox relies on the following legal mechanisms for cross-border transfer:
- EU-US Data Privacy Framework (DPF). Google LLC is DPF-certified (verify at https://www.dataprivacyframework.gov/list). EU and EEA personal data transferred to Google LLC for AI processing relies on this adequacy decision.
- UK Extension to the DPF. UK personal data follows the same mechanism via the UK's adequacy extension.
- Standard Contractual Clauses (SCCs). For data subjects not covered by the DPF (e.g., MENA tenants under our Business/Workforce tiers), we attach the EU SCCs Module Two (controller-to-processor) and Module Three (processor-to-sub-processor) as Annexes to our Data Processing Addendum.
If the DPF is invalidated by a future court ruling (Schrems III, pending), we will switch immediately to SCC-only operation. We monitor DPF status every 90 days.
Data residency for Business and Workforce tenants: Business administrators can choose data residency at tenant creation. Options: us-central1 (default), eu-frankfurt (Germany), me-central1 (Doha, Qatar). Workforce administrators get the same options. Consumer users (Free / Plus / Pro on individual billing) are pinned to us-central1.
6. How long we keep your data
| Category | Retention while account active | Retention after account deletion |
|---|---|---|
| Account identity + display name | Indefinitely | Deleted within 7 days |
| Messages (ciphertext) | Indefinitely | Deleted within 7 days |
| Voice/media blobs | Indefinitely | Deleted within 7 days |
| AI memory graph (people, facts, search index the AI builds across your messages) | Indefinitely | Deleted within 7 days when account is deleted; or instantly when you tap "Clear AI memory" in Settings |
| Per-message transcripts + summaries (attached to the message they describe) | Indefinitely | Deleted with the message (when you delete it or your account) — and cleared instantly, across all your messages, when you tap "Clear AI memory" in Settings |
| Subscription state | Indefinitely | Deleted within 7 days; some Apple-side records persist on Apple's servers per their policy |
| Consent timestamps | Indefinitely (audit) | Anonymized to a one-way hash; retained for 7 years per FTC ROSCA §3.9 |
| Audit log | Indefinitely (security + abuse-prevention) | Anonymized to a one-way hash; retained for 7 years |
| Device push tokens | Until you revoke the device, or up to 90 days of inactivity | Deleted within 7 days |
| Backups | 7-day rolling encrypted backups | Deletion propagates within 7 days |
You can trigger immediate deletion at any time:
- Settings → Account → Delete account — deletes everything you own.
- Settings → Privacy → Clear AI memory — erases the AI-derived data we hold about you: the derived memory graph (people/facts it learned and its search index), the per-message transcripts and summaries attached to your messages, post-call insight summaries, the learned drafting-voice corpus, and your Ask question/answer history. Your encrypted messages, voice notes, and media themselves are left intact — only the AI-derived plaintext built from them is removed. (Extracted tasks in your Work tab are your saved to-dos and are removed with the message or your account, not by this control.)
7. Your rights
Depending on where you live, you may have one or more of the following rights. Telbox honors all of them on a worldwide basis; the per-jurisdiction list is for clarity.
7.1 Universal (every user, every jurisdiction)
- Access — request a copy of the personal data we hold about you. Use Settings → Privacy → Export my data, or email privacy@telbox.ai.
- Correction — fix inaccurate or outdated data. Most fields are user-editable in the app; email us for the rest.
- Deletion — delete your account and all associated data. Use Settings → Account → Delete account, or email us.
- Restriction — limit what we process. Use Settings → Privacy → AI mode: Off to stop AI processing while keeping your messages.
- Portability — receive your data in a machine-readable JSON format. Use Settings → Privacy → Export my data.
- Withdrawal of consent — turn AI off (per conversation or entirely) at any time. Withdrawal stops future AI processing immediately; content already processed cannot be recalled from our AI processor.
- Complaint — lodge a complaint with the data protection authority in your country.
7.2 European Union / European Economic Area / United Kingdom
- All rights listed in §7.1.
- Additionally, the right to object to processing under GDPR Art. 21.
- Lawful basis for the AI processing we do for you: your consent (Art. 6(1)(a) GDPR). Where that processing works from a recording of your voice — specifically the optional voice-cloning feature (§10), which you must explicitly enable — we rely on your explicit consent (Art. 9(2)(a) GDPR). (Voice-note authenticity signing, §9, uses a random device key and does not process a biometric identifier.)
- Right to lodge a complaint with your national Data Protection Authority. The EDPB list of authorities is at https://edpb.europa.eu/about-edpb/about-edpb/members_en.
7.3 California (US)
- All rights listed in §7.1.
- Right to know what categories of personal information and sensitive personal information we collect (this policy is that disclosure).
- Right to opt out of "sale or share" of personal information for cross-context behavioral advertising. We do not sell or share for advertising purposes; the "Do Not Sell or Share" link on our website is provided as a CCPA-compliance affordance.
- Right to limit use of sensitive personal information (CCPA §1798.121). Sensitive personal information may include the voice recording you provide if you opt in to voice cloning (§10). We do not create a biometric voiceprint identifier of you (voice-note authenticity signing, §9, uses a random device key). The "Limit Use of Sensitive Personal Information" link on our website applies to the voice-cloning recording.
7.4 United Arab Emirates
- All rights listed in §7.1.
- Plus the rights listed in the UAE Personal Data Protection Law (PDPL), Federal Decree-Law No. 45 of 2021, Articles 13–19. These include the right to information (Article 13), the right to access (Article 14), the right to correction (Article 15), the right to erasure (Article 16), the right to restrict processing (Article 17), the right to data portability (Article 18), and the right to object (Article 19). You may file a complaint with the UAE Data Office for inquiries we do not resolve to your satisfaction.
7.5 Kingdom of Saudi Arabia
- All rights listed in §7.1.
- Plus the rights listed in the KSA Personal Data Protection Law, Royal Decree M/19 of 1443H, Articles 4–13. These include the right to information, the right to access, the right to correct, the right to erasure, the right to restrict processing, the right to object, and the right to file a complaint with the Saudi Data and Artificial Intelligence Authority (SDAIA) or the National Data Management Office (NDMO).
7.6 Egypt
- All rights listed in §7.1.
- Plus the rights listed in the Egyptian Personal Data Protection Law (Law No. 151 of 2020), Articles 2–9. Telbox will appoint a local representative in Egypt as required by Article 35 of Law No. 151 / 2020 before Egypt becomes a primary market; until then, Egyptian residents may exercise their rights by emailing privacy@telbox.ai and we will route the request through our DIFC-based privacy counsel.
7.7 How to exercise your rights
To exercise any right above:
1. Use the in-app affordance when one exists (Settings → Privacy → Export my data, Settings → Account → Delete account, etc.). The in-app path is the fastest. 2. If no in-app affordance covers your request, email privacy@telbox.ai with the subject line "[GDPR / CCPA / PDPL] data subject request" and describe what you want. 3. We acknowledge within 5 business days and complete the request within 30 days (45 in jurisdictions that allow extension, with notice to you). 4. We may need to verify your identity before fulfilling the request — typically a one-time-passcode sent to the phone number or email tied to your account.
You will never be charged a fee for exercising a data-subject right. We do not penalize you for asking. We do not require you to upgrade your subscription to use a right.
8. Children
Telbox requires all users to be at least 13 years old, and asks for your date of birth at sign-up so accounts below that age are not created. We do not knowingly collect data from children under 13 (USA, COPPA), under 16 (EU/EEA default), or under 18 (UAE/KSA general). If you believe a child has signed up, email privacy@telbox.ai and we will delete the account within 7 days.
9. Voice-note authenticity signatures
Telbox attaches a cryptographic authenticity signature to voice notes. A per-device signing key — an Ed25519 keypair generated automatically on your device, whose private half never leaves the device — signs each voice note's audio. Recipients' apps verify the signature to confirm the note came from your device and was not altered or synthesized by a third party.
This is not a voiceprint or biometric feature. The signing key is a random cryptographic key. It is not derived from, and does not measure, the acoustic characteristics of your voice, and Telbox does not create, store, extract, or match a voiceprint, voice template, or other biometric identifier of you. Because no biometric identifier is created or collected, this feature is not subject to biometric-specific consent regimes (for example, the Illinois Biometric Information Privacy Act or GDPR Article 9); it is ordinary device-key cryptography, covered by the general processing described in §2.
What we store: the public half of your device signing key, registered to your account so recipients can verify your signatures. We do not store a voiceprint or any biometric template. Raw voice-note audio is stored only as the end-to-end-encrypted blob described in §2.3, which we cannot read.
Retention / deletion: the public signing key is retained while your account is active and removed when you delete your account (§6). Signatures already attached to voice notes you have sent remain on those notes.
Separately, our voice-cloning feature (§10) does process a recording of your voice to build a synthetic voice on your explicit request; the disclosures and controls for that feature — including that it is optional and account-scoped — are in §10.
10. Voice Cloning (Pro tier)
Voice cloning lets Telbox synthesize speech in your own voice. It is a biometric feature (your voiceprint), so we handle it under the special-category rules of GDPR Art. 9 and equivalent laws:
- Enrollment is opt-in and requires your deliberate action: you start enrollment yourself from Settings and record the enrollment audio yourself; we never build a voiceprint passively or from your ordinary voice notes. Before you record, the enrollment screen shows a privacy notice describing what we build from your recording and how to remove it. The recording is used only to build your clone and is stored as encrypted blob storage (§2.3); deleting your account or your clone erases the enrollment audio (§ account deletion).
- You can delete your voice clone at any time from Settings; this removes the voiceprint and its enrollment audio.
- Telbox reserves the right to disable Voice Cloning on any account where we have a reasonable belief of misuse (impersonation, fraud, defamation).
- Provenance watermarking is not currently applied. Audio generated from your voice clone does not carry an inaudible provenance watermark today. We are exploring provenance-watermarking for a future release; we will describe it here, and represent it as active, only once it actually ships.
- See https://telbox.ai/voice-cloning-policy for the full voice-cloning terms.
11. EU AI Act transparency
When Telbox uses AI to generate content for you (transcripts, summaries, AI-drafted reply chips), the iOS app labels the AI-generated content with a visible "AI" badge. This satisfies Article 50(1) of the EU AI Act (Regulation (EU) 2024/1689). Article 50(2) also calls for synthetic audio to be marked in a machine-detectable form; as noted in §10, audio generated by our voice-cloning feature does not currently carry such a machine-detectable watermark. We are working toward that Article 50(2) marking and will describe it here once it is in place.
12. Security
- Transport: every message, voice note, and call is encrypted between your device and the recipient's device. We use X25519 key exchange, AES-256-GCM authenticated encryption, Ed25519 signatures, HKDF-SHA256 key derivation — all RFC-published and NIST-recognized.
- At-rest: Telbox stores message ciphertext and media blobs in Google Cloud, encrypted at rest by Google's default GCS / Cloud SQL encryption.
- AI processor isolation: when you turn AI on, your messages are sealed to an AI processor's public key (X25519). The AI worker decrypts in-process inside our infrastructure; the plaintext exists only in memory for the duration of the AI call.
- Internal access: a small number of Telbox engineers have administrative access to the production environment for operational support. Production access requires named two-person review for any data-touching operation and is audit-logged.
- Vulnerability disclosure: report vulnerabilities to info@telbox.ai. We respond within 5 business days.
13. Changes to this policy
If we change anything material in this policy, we will:
- Post the new policy at https://telbox.ai/privacy with a new "Last updated" date.
- Show you an in-app notification before the next time you use a feature affected by the change.
- For substantive changes that affect AI processing or data flows, require you to explicitly accept the new policy before continuing.
Non-substantive changes (typos, formatting, link updates) are made without notice; the version number stays the same.
14. Contact
- General privacy questions: privacy@telbox.ai.
- Data subject rights requests: privacy@telbox.ai with subject line "[GDPR / CCPA / PDPL] data subject request".
- Vulnerability reports: info@telbox.ai.
- Mail: Telbox AI Labs LTD, 128 City Road, London EC1V 2NX, United Kingdom.
If we are slow to respond, escalate to founder@telbox.ai — the founder commits to a personal response within 5 business days while the team is small.
For privacy advocates or researchers studying our practices: we welcome scrutiny. Our public data-handling page at https://telbox.ai/architecture/ describes the same data flows we describe in this policy, at engineering detail, and deeper internal architecture documentation is available to qualified auditors and researchers on request. If you find a contradiction between that page, this policy, and what the app does, email info@telbox.ai — we treat that as a bug to fix.
15. Version history
- 3.3 — July 22, 2026. Provider-naming consistency pass. Removed the AI vendor's name from the *reassurance prose* in §3.7 and §7.1 and the disclosure-mirror prose in §3.7/§4, describing the no-training guarantee by mechanism instead. The processing entity remains named where data-protection law requires it — the §3.6 sub-processor list and the §5 international-transfer mechanism (DPF/SCC) — and the infrastructure/at-rest disclosures are unchanged. No substance, routing, or commitment changed; this aligns the persuasive prose with the site/App-Store "mechanism, not vendor" posture while preserving every mandatory identification.
- 3.2 — July 19, 2026. Accuracy correction ahead of public launch. §2.9 previously stated flatly that Telbox does not read your contacts list and that location is used only when explicitly shared in a conversation. Both were false on Android, where the Ask feature attaches contacts, calendar, and coarse location to a submitted question once the corresponding Android permission is granted (shipped and disclosed in-app under Settings → Privacy, but absent from this policy — and calendar was not declared at all). Both §2.9 bullets now scope their denials to background/advertising/profiling use, and the new §2.10 documents the three Ask context sources, exactly what each attaches, the gating permission, and that this context is decrypted server-side like any other AI request. No behaviour changed; this corrects the description to match what has been shipping. Play Data Safety answers updated in the same pass to declare Calendar. Also in 3.2: the AI processor is now described by mechanism — a paid commercial contract prohibiting training on your content — rather than by naming the vendor's model/product, and the no-training commitment is no longer substantiated by citing a specific product's terms URL. The processing entity remains named in the §3.6 sub-processor list, because data-protection law requires sub-processors to be identifiable; only the model/product branding was removed. Substance of the commitment is unchanged.
- 3.1 — July 9, 2026. Published. Incorporates the July 4 accuracy reconciliation and makes server-side AI decryption explicit (§3.0). Corrected §2.2 metadata inventory (stored vs transient); §2.9 location and call-segment audio accuracy; §10 voice-cloning safeguards as shipped (no watermark claim); §11 EU AI Act Art. 50(2) as not-yet-implemented; "Clear AI memory" now clears the memory graph and per-message
ai_payloadtranscripts/summaries. Engineering rationale:docs/product/privacy-copy-reconciliation-2026-07-04.md. - 3.0 — June 11, 2026. Aligned with the 2026-05-19 single-endpoint architecture: AI processing routes through the same no-training endpoint on every tier; AI features documented as on from the start, with per-conversation and account-wide off switches; retired the free-tier training disclosure and the tier-based routing description; subscription tiers now described as changing usage limits only.
- 2.0 — May 18, 2026. Rewrite to distinguish free-tier (trainable) and paid-tier (no-training) AI processing flows; added Apple subscription disclosure; added recipient-consent gate explanation; added per-jurisdiction rights breakdown; added EU AI Act transparency note; added Voice Identity Signing biometric disclosure; added sub-processor list reference. (Superseded 2026-05-19 by the single no-training endpoint architecture.)
- 1.0 — April 30, 2026. Initial closed-alpha policy.