← TellEddy

TellEddy Privacy

Where your voice and your text go — and where they don’t.

Last updated 20 September 2026 — and this was a real revision, not a date bump. We read this page against the code line by line, found a number of places where it was out of date, understated, or describing a feature that doesn’t exist, and fixed every one of them in the open. Wherever an earlier version told you something that wasn’t right, it says so on the spot rather than quietly correcting itself.

TellEddy listens to your microphone and reads text out loud. That’s inherently sensitive territory, so here’s exactly what happens to your data, broken out by feature.

The short version

Dictation: turning your voice into text

Apple Speech (default)

Audio is processed by Apple’s SFSpeechRecognizer. When macOS has the on-device speech model for your language, TellEddy sets requiresOnDeviceRecognition and the audio never leaves your Mac.

And here is the caveat this page used to leave out. That flag is only set when macOS says the on-device model is available for your locale. When it isn’t — a language Apple hasn’t shipped one for, or a model that hasn’t downloaded yet — Apple’s framework transcribes over Apple’s servers instead, and TellEddy currently neither detects that nor tells you. Earlier versions of this page said “nothing leaves your machine” flatly. That was true for most people and not guaranteed for everyone, and the difference is exactly the kind we’d rather you heard from us. Either way it is Apple’s framework and Apple’s policy, and Bear & Eddy sees none of it.

Groq (optional, and this one is the cloud)

Apple Speech struggles with accented English and noisy rooms. Groq doesn’t, which is why it’s offered — but it earns its own warning label: choosing Groq means your recorded audio is uploaded to Groq’s servers on your own API key. Not a transcript. The audio. It is off unless you go turn it on, and Apple Speech stays the default. Subject to Groq’s privacy policy.

(We used to ship WhisperKit here as a second on-device option. It was dropped in May 2026 — Apple Speech and Groq cover both ends of the trade-off and the model-management experience never got good enough to justify a third.)

AI refinement (optional)

TellEddy can clean up and rework text with a language model. Two of the things this page used to list here never involve Claude at all, and that’s worth correcting in your favour: the punctuation cleanup after a dictation, and the Notepad polish that runs as you pause to think, are pinned to on-device Apple Intelligence. That path is hard-coded to refuse every other model — if Apple Intelligence isn’t available on your Mac, the polish simply doesn’t run. Nothing typed in that hot lane is ever sent anywhere.

What can reach a cloud model is what you press a button for: the Notepad’s tone and agent rewrites, Study’s key words, notes and Guided Read, and the script behind a podcast. (Summarize & Read is on-device only, like the polish.) Those are opt-in, and there are two doors into them with genuinely different privacy stories. So here they are separately.

Your own key

Paste an Anthropic API key and the text goes from your Mac straight to Anthropic on your account. We never see it and we’re not in the billing path. Subject to Anthropic’s privacy policy.

Eddy’s cloud — the relay we actually run

Here’s the honest reason this exists. A Claude Pro subscription buys you exactly nothing at Anthropic’s developer console — different account, different bill — so “just bring your own key” quietly meant “go open a second paid developer account,” and almost no teacher, parent, or student was ever going to do that. Eddy’s cloud is the other door: refinement on our Anthropic key, included with a TellEddy license.

And it costs you something in privacy, so we’re going to say it plainly rather than let you find out later. This path is a relay. Your text passes through a Bear & Eddy server on its way to Anthropic. And “your text” is broader than it sounds. It is not your dictation being tidied up — that stays on your Mac, as above. It is the Notepad rewrites you ask for, the reading when Study makes key words or notes from it, and the whole article when you turn one into a podcast. A chapter can go through here, not just a sentence — and since 0.15.0, with a book imported, chapter after chapter in turn. We don’t store it, we don’t log it, and we don’t train on it — the relay reads the usage numbers that come back so it can count the request against your monthly allowance, and that is the whole of our interest in the text. The request also carries your license code, so the relay knows whose allowance to charge — and your email is inside that code, so this is the path on which we learn your address.

Two more things about the machine itself, because “a Bear & Eddy server” is vaguer than you deserve. It is a Cloudflare Worker, so Cloudflare handles your text in the clear on its way to Anthropic, the same way any site’s host does. And before it checks anything else, the relay writes the IP the request came from into a rate-limit counter that expires within two minutes — so “we don’t store it” is a statement about your text, not a claim that nothing at all is written down.

There’s a fuller account under License codes below. But “we couldn’t see it even if we wanted to” is a claim we no longer get to make about this one, so we’re not making it. The app names the destination before it sends anything, and your own key is always there if you’d rather we weren’t in the middle at all.

Read-aloud: turning text into voice

Engine
Where your text goes
Apple Speech
On-device. AVSpeechSynthesizer. Nothing leaves your Mac.
Apple Personal Voice
On-device. Your trained voice profile stays in iCloud’s Personal Voice store under Apple’s control.
Kokoro-82M
On-device. Runs on the Neural Engine via FluidAudio. The model downloads from Hugging Face the first time you use an Eddy voice — several hundred megabytes on a Mac, far smaller on iPhone. That download carries no text and nothing identifying beyond your IP address, and it can happen again after an update changes the model format. After it, synthesis is entirely local.
OpenAI TTS
Sent to OpenAI’s API with your key. Subject to OpenAI’s privacy policy.
Cartesia
Sent to Cartesia’s API with your key. Subject to Cartesia’s privacy policy.
ElevenLabs
Sent to ElevenLabs’ API with your key. Subject to ElevenLabs’ privacy policy.
Google Gemini
Only used to voice a two-host podcast, and only if you pick it — the default podcast voices are on-device Eddy voices. The finished script is sent to Google’s Generative Language API with your key. Subject to Google’s privacy policy. The script itself was written earlier, by whichever text model you chose — see below.

When you pick a cloud voice, TellEddy opens a direct connection from your Mac to that provider. No proxy, no relay, no Bear & Eddy server in the middle — we literally couldn’t see your text even if we wanted to. Speech is fully bring-your-own-key and stays that way. Text refinement is the one place that changed, and it has its own section above.

One thing in this area is not speech, and it would be easy to file under “voices” and miss: the podcast script. Before any voice reads anything, the whole article is written into a two-host script by whichever text model you picked — Apple Intelligence on your Mac, Claude on your own key, or Eddy’s cloud, in which case the entire article passes through our relay first. The confirmation sheet names that model before it starts.

Listen Later & the iPhone companion

Listen Later is the queue you build on your Mac and pick up on iPhone — and it runs the other way too: share something to TellEddy from the iPhone share sheet and the phone fetches that article from the publisher and renders the audio on-device before it syncs back. No Bear & Eddy server is in the path in either direction.

What syncs through your iCloud private database (CloudKit) is the whole item: the text itself, its rendered audio and thumbnail, the URL and title, which app you captured it from, which voice read it, how far you got, and any error the render hit. Turn an item into a podcast and the script Eddy wrote rides along too, in a record of its own. Earlier versions of this list named only the URL, title, thumbnail and audio — which understated what the queue carries, and the text was the conspicuous omission.

Apple encrypts that database, scopes it to your Apple ID, and makes it inaccessible to anyone but you. Bear & Eddy doesn’t run sync infrastructure and has no read access to your queue. There is no Bear & Eddy server anywhere in the sync path, and no way for us to see what you queued or listened to.

“Share for the web” is the one case where audio leaves your private database — only ever because you clicked the button, but be clear-eyed about what the button does. It uploads that item’s rendered audio to our storage and hands you a telleddy.com/l/<id> link that plays in any browser, no app and no sign-in required.

And it uploads more than the audio. The title, the source URL, the site it came from — or, for something you captured out of an app rather than from a link, that app’s name, so sharing a selection you took from Mail or Slack publishes that — the voice that read it, and the email address on your license, which the listen page prints at the top of the player as the person who shared it. So sharing a paywalled article publishes your email address, and what you were reading, to anyone who opens that link. That’s a defect in how we built it rather than a decision, but it is what ships today and we’d rather say so than let you discover it on a page you sent a friend. Until it uses a name you chose, share with that in mind.

One consequence worth spelling out, because it isn’t obvious from either end: study notes you send to your phone arrive as ordinary Listen Later items, stamped as coming from TellEddy Learning. That means they carry the same Share button as anything else in the queue — so a set of notes about a chapter can be published to a public link, with your license email on it, in the same two taps as an article.

Which means it is an unlisted link, not a private one. There is no password on it, and anyone the link reaches can play it — that is the whole point of a link you can text to a friend, but it’s worth knowing before you share something you’d rather keep close. And there is currently no revoke button. An earlier version of this page said you could take a share back at any time. That was wrong, we’re sorry, and until we build it the honest advice is to treat sharing a listen as permanent. Email us and we’ll delete one by hand in the meantime.

Study & Learning

Turn on Learning in Preferences and TellEddy can take a reading and produce key words, study notes, and flashcards from it. It is off by default. A reading arrives one of three ways: text you have selected in another app, a PDF, text or Markdown file you open with “Study a file…”, or — new in 0.15.0 — a whole book, split into chapters from the file’s own bookmarks or headings. (There is no paste path and no drag-and-drop; earlier versions of this page said there was.)

When it runs on Apple Intelligence, the reading never leaves your Mac. When you point it at a cloud model, the reading goes to that model, the same as any other cloud feature here — and if that model is Eddy’s cloud, it travels through our relay on the way, exactly as described above. So it is worth knowing which model you picked.

And it is worth knowing how much goes at once, because 0.15.0 changed that. A Claude run now sends the document in stretches of up to about 120,000 characters — roughly a forty-page reading in a single request — where the on-device path still works in pieces of about 6,000. Standard depth, which is the default, writes notes section by section, so one study run is a series of requests rather than one. And a book is the big one: you approve the cloud model once, then press Study, and the chapters you ticked go out one after another while you do something else. That is the honest shape of it — one press can send a whole book.

Study notes stay on the Mac unless you move them, and there are exactly two ways to move them: a cloud voice reading them, and Send to phone. Both are below. Copying them or saving them to a file moves them nowhere. Reading them aloud depends on which voice you picked — an on-device voice keeps them here, and a cloud voice sends the notes to that provider on your key, the same as any other text you have Eddy read. The school-age rule below governs that too. The 8 September version of this paragraph said none of that moved them anywhere, full stop. That was wrong about the cloud voices, and it’s corrected above.

Send to phone is the one action that does move them. It shipped in 0.14.5 — an earlier version of this page described it before it existed, which was our mistake, and this is the paragraph we promised would change first. It queues the notes as a Listen Later item, and two things about it are worth knowing. The notes text reaches your private iCloud database the moment you send, not once the audio is ready — so it is there even if the render fails. And the audio is made on-device at both ends, by Apple Speech or Eddy voices: on this Mac, or on the phone if it picks up an item the Mac had not finished. Neither renderer has a cloud branch at all, so a cloud voice provider never sees study notes you send to your phone. The school-age rule applies here too, and Eddy says so on screen when it changes the voice.

There’s one rule we hard-coded because we didn’t want to leave it to a checkbox nobody reads: if the material is marked as being for a school-age reader, TellEddy will not send it to a cloud model. It quietly runs the work on-device instead and tells you it did. The license holder can turn that off deliberately in Preferences → Learning — but it has to be turned off on purpose, by an adult, and a reading-level setting can only ever make the rule stricter, never looser. The same rule governs which voice reads it aloud.

Here is precisely when it fires, because “school-age” is doing a lot of work in that sentence. It fires when “Who it’s for” is set to middle or high school, and when it is set to college or learning English and the reading level is below ninth grade. It does not fire for the teacher-or-tutor setting, at any reading level — material a teacher is preparing is treated as an adult working from published text, and it goes to the model you picked. If your Mac can’t run Apple Intelligence there is nothing to downgrade to, so a run that would break the rule is refused outright rather than quietly moved.

API keys (BYOK)

Cloud engines use your account and your key — we call this “bring-your-own-key.” You paste a key in once and TellEddy stores it in the macOS Keychain. The Keychain encrypts these at rest and only TellEddy can read them back on your machine.

Keys never get written to logs and never to disk in plaintext. This line used to add “never to crash reports (there aren’t any)”, which stopped being true in v0.6.2 — there are crash reports now if you opt in, and the reporter scrubs breadcrumbs, tags and file paths before anything is sent. If you uninstall TellEddy, the keys stay in your Keychain until you remove them yourself — they belong to you, not the app.

Recognition Hints & learn-from-dictation

TellEddy lets you add proper nouns and jargon as “Recognition Hints” so the dictation engine spells them right. Optionally, the app can learn frequently-used words from your dictation history and surface them as hint candidates.

TellEddy stores word frequency counts only — never full transcripts. Stopwords and words under three characters are filtered, the store is capped, and everything lives in NSUserDefaults on your Mac. Nothing here is transmitted anywhere.

Two corrections to what this section used to say, both in the direction of “it does more than we told you”. This feature is on by default, not off: counting starts the first time you dictate, and the switch in Preferences → Dictation turns it off. And a word does not have to appear several times to be surfaced — TellEddy offers the eight most-dictated words that aren’t already hints, which early on can include something you said once.

There is a second local ledger in the same spirit, which this page has never mentioned. When an Eddy voice meets a word it has to guess the pronunciation of, TellEddy writes that word and its guess down so you can teach it the right one. That covers anything you have had read aloud, it is on by default, it holds the word and the guess and nothing else, it never leaves your Mac, and it switches off in Preferences.

This section used to describe a Contacts feature. It doesn’t exist. It said TellEddy could read names from your address book and add them to your hints. There is no such code in the app and never has been — no Contacts permission is requested, and macOS wouldn’t let the app ask without a declaration it doesn’t carry. Your address book has never been touched. We’re sorry for the scare; a privacy page describing a read that never happens is its own kind of failure.

License codes

TellEddy is licensed with offline Ed25519-signed codes. We hand you a signed code; the app verifies the signature using a public key built into the binary. Checking whether your license is valid happens entirely on your Mac — there is no server to call and nothing to phone home to.

But your license code does leave your Mac, and the email you bought with is inside it. An earlier version of this page said that email is not transmitted anywhere. That was wrong, and it’s the kind of wrong that matters, so here is the real shape of it. The code is a signed string with your email in its payload, and TellEddy sends the whole code to our server any time it has to prove you’re licensed: every request through Eddy’s cloud, every check of your monthly allowance, every gift you send, and every time you open the Eddy Report. If you use any of those, we receive your email address along with the request. We don’t sell it, market to it, or build a profile from it — but we do receive it, and you should hear that here rather than work it out from a request header.

And there’s one more path, which an earlier draft of this very paragraph got wrong by promising your license stays put. It doesn’t. When you activate, TellEddy writes the license — code, email and all — into your private iCloud database, so the iPhone app can tell you’re licensed without you typing anything twice. That’s your iCloud under your Apple ID, encrypted, and we have no read access to it. But it is your email leaving the Mac, it happens whether or not you ever touch the cloud features above, and you deserve to know it from here.

Your clipboard

This page has never mentioned the clipboard, and it should have, because TellEddy touches it in the ordinary course of working. Four places, all of them on your Mac and none of them sending anything anywhere.

Permissions TellEddy asks for

macOS grants these one at a time through its TCC permissions system. You can revoke any of them from System Settings → Privacy & Security at any time.

Updates

TellEddy checks for updates by fetching a small XML file from telleddy.com once a day. The request includes your app version and macOS version (standard browser User-Agent stuff) and nothing else. Updates themselves are EdDSA-signed; the app verifies the signature before applying them. You can turn auto-update checks off in Preferences.

What we don’t do

What we do have — because “we collect nothing” stopped being true

This page used to open with “TellEddy has no servers. We collect nothing.” That was true when it was written and it isn’t anymore, so rather than quietly soften the sentence, here is the whole list of what now exists.

For the counter server: visitors’ IP addresses touch it the way they touch any website — it uses them for a rate-limit counter that expires within two minutes, and keeps no log of them after that.

Changes to this page

If we add a feature that changes any of the above — a new cloud engine, opt-in crash reporting, anything — we’ll update this page and call it out in the in-app release notes. The current version of TellEddy this page describes is the latest one on the TellEddy site.

Questions about privacy or security? Email drew@bearandeddy.com.