Your data,
on your Mac.
Tyll is built so your content stays with you. Here, in plain words, is which data we actually process when you visit this site, write to us, subscribe to emails, buy Tyll, or enable optional features.
Last updated · June 2026
Short and honest
- By default, the app processes your recordings and text entirely on your Mac.
- This website uses no advertising cookies and no marketing trackers.
- We use Cloudflare for hosting, security, simple aggregated web statistics and our Cloudflare databases.
- We only process what is technically or contractually necessary, and never share anything for advertising.
Controller
Peter RudelWiltbergstr. 66/1
13125 Berlin
Germany
Our principle
By default, the app processes your recordings and text locally on your Mac, with no account and no upload to us. This policy describes what happens when you visit tyll.app, write to us, sign up for emails, buy Tyll, or enable optional integrations in the app.
When you visit this website
Our website is delivered through Cloudflare (Cloudflare, Inc.). Cloudflare processes technically necessary connection data such as IP address, date and time of access, requested URL, referrer, browser and device information, plus security and performance signals.
We also use Cloudflare Web Analytics and the analytics views provided by Cloudflare. For this, Cloudflare may load a small performance beacon or evaluate measurement data from Cloudflare's infrastructure operation. The analytics give us simple aggregated statistics such as page views, loading times, Core Web Vitals, approximate origin, browser or device types. According to Cloudflare, the Web Analytics/RUM beacon uses no cookies, no localStorage, no sessionStorage, no IndexedDB and no fingerprinting.
We use these statistics only to understand whether the website works technically and which pages are reliably reachable. We do not use this data for advertising, retargeting or personal usage profiles.
The legal basis is our legitimate interest in secure, stable and understandable website operation under Art. 6 (1) (f) GDPR. Because we do not use cookies, localStorage, fingerprinting or comparable consent-requiring storage or access technologies for this, we do not ask for consent under section 25 TDDDG.
Fonts
We serve the Inter typeface locally from our own server. Loading the fonts creates no connection to Google or any other third party, and no data is transmitted to third parties.
Contact form
When you write to us through the contact form, we process the data you provide, namely your name, email address, language and your message, to answer your request. The form contains a required checkbox where you acknowledge the privacy notice.
We use the service Resend (Resend, Inc.) as a processor to send the message to us and the confirmation email to you. The message is then handled in our communications mailbox; for that we use Gmail or Google as an email and communications provider. Google may process communication data such as sender, recipient, subject, time and email content. Depending on the content of your request, the legal basis is handling pre-contractual or contractual matters under Art. 6 (1) (b) GDPR or our legitimate interest in handling, documenting and preventing abuse of requests under Art. 6 (1) (f) GDPR. The checkbox is not a separate advertising or newsletter consent.
We generally store contact requests until they are finally handled and then for up to 12 months so we can understand follow-up questions. If a request is contractually or legally relevant, we store it until the regular limitation period expires, usually three years from the end of the year in which the matter was completed.
Newsletter and product notifications
If you sign up for news, product notifications or a waitlist, we use your email address only for that communication. Signup uses double opt-in: you receive an email and are added to the active list only after confirming it.
To prove signup, we store the following data in our Cloudflare-hosted database:
- Email address and normalized email address
- Signup status, signup source, locale and consent text version
- Creation, update, confirmation and unsubscribe timestamps
- Hash of the confirmation token and hashes of IP address and user agent during signup, confirmation and unsubscribe
- Resend contact ID, delivery and sync status, and technical event and job data for confirmation, contact creation and unsubscribe
We do not store the confirmation token itself in plain text.
For sending the confirmation email and later product notifications we use Resend (Resend, Inc.) as a processor. Only after confirmed double opt-in do we create the email address as a marketing contact in Resend. The legal basis is your consent under Art. 6 (1) (a) GDPR.
You can unsubscribe at any time through the link in each email or by writing to us. When you unsubscribe, we immediately mark the local record as unsubscribed and delete the marketing contact in Resend. If Resend is unavailable at that moment, we keep the delete job locally and retry the deletion. We store the double opt-in proof after unsubscribe usually for up to three years from year-end so we can prove the consent and withdrawal.
Purchase and license
When you buy Tyll, the payment is handled by our payment provider Paddle (Paddle.com Market Ltd). Paddle acts as the seller (Merchant of Record) and processes the data needed for the purchase, such as your email address, payment and billing data, on its own responsibility.
From Paddle we receive through webhooks and the Paddle API only the information we need to provide, manage and support your license, in particular customer and transaction identifiers, email address, product data and payment status. Payment details, tax calculation and invoicing remain with Paddle.
After a completed purchase, our license server creates the license key. We send the license key to you by email through Resend as our processor. We do not pass the license key to Paddle for storage in the invoice or Paddle customer account.
For activation, validation, transfer or deactivation, the app sends your license key together with a locally generated installation identifier to our license server. The license server creates hashes and stores the license-key hash, license status, activation limit, the hashed installation identifier, the activation ID, and activation, validation, transfer and deactivation timestamps. For purchase-related matching, we store only one HMAC derived from the Paddle transaction identifier, not the transaction identifier itself. The license server does not store a Mac name, hardware serial number, app version or payment details.
The legal basis is performance of the contract under Art. 6 (1) (b) GDPR and our legitimate interest in protection against unauthorized use under Art. 6 (1) (f) GDPR. Statutory tax and commercial retention obligations remain unaffected.
When you use the Tyll app
Tyll processes your recordings, transcripts and text entirely on your Mac. By default this content is not uploaded, and we never receive it. The app needs no account.
The app contains no analytics, tracking or telemetry. We do not record which features you use.
The app contacts a server only in a few clearly defined cases.
- License activation and validation, as described above under Purchase and license.
- Update checks through our update feed, where the app looks whether a new version is available.
- Fetching notes about news and relevant add-on offers shown inside the app. The app only retrieves content and transmits no usage or content data.
These connections process technically necessary connection data such as your IP address, because no connection is possible without it. We do not use this data to identify you or to analyze your behavior. The legal basis is our legitimate interest in a working, up-to-date and secure app under Art. 6 (1) (f) GDPR.
Local contacts and speaker profiles
Tyll can store contacts, email addresses, speaker assignments and technical speaker profiles locally on your Mac so you can recognize people in transcripts or complete recurring workflows faster. These records are stored in your local app database and are not transmitted to us.
If you use Tyll in a professional setting, you are responsible for informing the affected people and having a suitable legal basis for recording, transcription, speaker assignment and local storage. We provide the software, but we do not receive these local contents.
Optional AI providers and integrations
Some enhancement and integration features are optional and off by default. If you enable an external AI interface or integration, the local default processing leaves your Mac for that specific add-on function. The app then sends only the content required for the function you triggered to the provider you configured, for example transcript segments, context segments, speaker labels, glossary terms and the task instruction generated by Tyll. The connection is made directly from the app using the credentials or API keys you configured, unless something else is expressly shown. Tyll provides the technical interface for this; the provider, account, endpoint and provider-side settings are selected by you. Tyll stores API keys and bearer tokens locally in the macOS Keychain.
Tyll currently supports OpenAI and Anthropic for this optional enhancement. OpenAI is called through the OpenAI Responses API; Tyll sets the store=false parameter. Anthropic is called through the Anthropic Messages API.
Our servers do not see or store content sent to external AI providers. For this user-configured use, we do not conclude our own contracts with the AI provider on the user's behalf and we do not operate the provider as our processor. The provider's own privacy terms, usage terms and account settings apply. To the extent personal data is processed, you decide the provider, purpose, account, target address and content of the transfer. If you use Tyll professionally, you are responsible for the lawfulness of recording, transcription and external AI use toward the affected people and should reflect that external processing in your own privacy notices or internal rules where needed. If transcripts contain special categories of personal data, you also need a suitable legal basis under Art. 9 GDPR before sending them to external providers.
Planned providers or plugin targets such as Google, Amazon Bedrock, Microsoft Azure, CRM systems or HubSpot are not active unless they are available in the app as selectable or connected integrations. As soon as an integration can send personal data to another external provider, we will name the provider, purpose, data categories, provider role and applicable transfer or security basis in the app or in this policy before you use it.
No advertising cookies, no marketing profiles
This website sets no advertising cookies, uses no retargeting and embeds no marketing trackers such as Google Analytics or Meta Pixel. We build no personal usage profiles and never share your data for advertising.
Recipients and processing outside the EU
We use only providers that are necessary for the relevant purpose. Cloudflare processes data for hosting, website protection, Web Analytics, Cloudflare Pages/Workers and Cloudflare D1. For Cloudflare we use Cloudflare's data processing terms. For transfers to the USA, Cloudflare states that it relies on the EU-US Data Privacy Framework and additionally on EU Standard Contractual Clauses.
Resend processes email data for contact replies, double opt-in, product notifications, contact creation, delivery status and unsubscribes. For Resend we use the Data Processing Addendum. Resend is a US provider; according to Resend, international transfers may rely on the EU-US Data Privacy Framework and the EU Standard Contractual Clauses included in its DPA.
Google processes communication data when you write to us or when we handle your request in our Gmail mailbox. This may include email address, name, subject, content, timestamps and technical delivery information. Depending on the service and processing, Google's privacy terms, data processing terms, the EU-US Data Privacy Framework and EU Standard Contractual Clauses may apply.
Paddle processes purchase, payment, tax, invoice and purchase-related license data as Merchant of Record and as an independent controller. Paddle.com Market Ltd is based in the United Kingdom. The United Kingdom is covered by a European Commission adequacy decision; further international transfers follow Paddle's privacy terms.
OpenAI, Anthropic and other external AI providers process content only if you enable the relevant optional AI enhancement and configure your own credentials. These providers are third-party providers selected by you, not our processors for Tyll's own server processing. Transfer bases, retention periods and further privacy terms follow the relevant provider terms and account settings.
You can request information about the concrete safeguards we use and, where available, copies of the relevant contractual basis at [email protected]. We do not share personal data with advertising networks, data brokers or social media tracking providers.
Providing your data
You do not have to actively provide data just to visit the website; technically necessary connection data is created automatically because otherwise the website cannot be delivered.
For the contact form, name, email address, message and the privacy checkbox are required. Without those details we cannot accept or answer your request through the form. If you write to us directly by email, we process the details contained in that email.
For newsletter or product notifications, your email address is required. Without an email address and double opt-in we cannot add you to the list. For purchase, license activation and license validation, the purchase and license data described above is required; without it, purchase, activation, transfers or license validation cannot work reliably.
Optional AI providers and integrations are voluntary. If you do not enable them or do not configure credentials, Tyll does not send content to those external providers and the relevant add-on feature is unavailable.
Retention periods
We delete personal data as soon as it is no longer needed for the relevant purpose and no statutory obligations prevent deletion. Currently this means:
- Website and security logs are generally stored only briefly, usually up to 30 days. In case of security incidents or abuse attempts, we may store them longer as long as needed for investigation and defense.
- Contact requests are stored until handled and then usually for up to 12 months; contractually or legally relevant communication until the regular limitation period expires, usually three years from year-end.
- Newsletter and waitlist signups are stored until unsubscribe. Proof of consent and unsubscribe is usually stored after unsubscribe for up to three years from year-end; the marketing contact in Resend is deleted on unsubscribe.
- License and contract data are stored for the license term and then usually until the regular limitation period expires, typically three years from year-end.
- Invoice, tax and commercial records are stored according to statutory retention duties, usually six or ten years.
- Local app contents such as recordings, transcripts, contacts and speaker profiles are not stored by us. You decide their retention in your local environment.
Your rights
Under the GDPR you have the following rights.
- Access to the data stored about you (Art. 15)
- Correction of inaccurate data (Art. 16)
- Erasure of your data (Art. 17)
- Restriction of processing (Art. 18)
- Data portability (Art. 20)
- Objection to processing (Art. 21)
- Withdrawal of a given consent with effect for the future (Art. 7 (3))
To exercise your rights, you can write to us any time at [email protected]. Withdrawal of consent does not affect the lawfulness of processing based on consent before withdrawal.
Data protection officer and automated decisions
We are not legally required to appoint a data protection officer and have not appointed one. You can reach us directly about privacy questions at [email protected].
We do not make automated decisions within the meaning of Art. 22 GDPR and do not create personal profiles for advertising or scoring purposes.
Right to complain
You have the right to lodge a complaint with a data protection supervisory authority about how we process your personal data. The authority responsible for us is the Berlin Commissioner for Data Protection and Freedom of Information. You may also contact the authority where you live.
Data security
Our website, API endpoints and license server are served exclusively over encrypted HTTPS, so your data is protected in transit.
We limit processing to the data necessary for the relevant purpose. Newsletter tokens, license keys, local installation identifiers and the purchase-related matching identifier are not stored in plain text, but as a hash or HMAC where that is sufficient for proof, activation, support or abuse prevention. Credentials for optional AI providers are stored locally in the macOS Keychain.
Access to production systems, Cloudflare databases, Resend, Paddle webhooks and license-administration functions is limited to the operationally necessary accounts and secrets. Errors and security events may appear in technical logs; we use those logs for stability, debugging and abuse prevention, not for advertising or profiling.
Status and changes
We update this policy when the technology or the legal situation changes. The version published here always applies.
This is a courtesy translation. The German version of this policy is legally binding.