Tephra Tephra
Privacy Policy

Privacy Policy

Last updated: June 19, 2026

Tephra is a voice-note app designed with privacy at its core. We believe your thoughts are yours alone. This policy explains what data Tephra handles, how it's used, and why we've built the app to keep as much as possible on your device.

Who Is Responsible (Data Controller)

The party responsible for personal data processed in connection with Tephra — the "controller" under the EU General Data Protection Regulation (GDPR / DSGVO) — is:

Matthias Aldorf
Oberer Sandrech 8
66482 Zweibrücken
Germany

hello@tephra.app

Tephra is operated by Matthias Aldorf as an individual, not a registered company. A full legal notice is available in the Impressum.

Data We Collect & How It's Used

Microphone Audio

Audio is temporarily recorded for the sole purpose of transcription. Transcription happens entirely on-device using WhisperKit, an open-source speech-recognition engine that runs on Apple's Neural Engine. The recording is deleted as soon as your note is saved, and it only ever exists on your device — it is never sent to any server. (If processing fails, the recording is kept on your device until you retry or dismiss it.)

Location

If you grant location permission, your city and country are tagged to notes using Apple's on-device geocoding, and approximate coordinates (rounded to roughly 100 m) are saved inside your own note files. Your location — the city, the country, and the approximate coordinates — stays on your device and inside your own note files; none of it is ever sent to the AI provider. Location tagging is optional and can be disabled at any time in your device settings.

Transcript Text

When you record a note, the transcribed text — together with the note's date and time — is sent for AI-powered formatting (title generation, cleanup, tagging, and entity linking). For Pro subscribers it passes through Tephra's server, which forwards it to OpenAI and keeps no copy. For BYOK (Bring Your Own Key) users, the text goes directly to the user's chosen AI provider — OpenAI, Google Gemini, Anthropic, or Groq — without passing through our servers. The same applies when you use "Ask Tephra": searching your notes happens on your device, and only short excerpts of the matching notes are sent to the AI to compose the final answer.

API Keys (BYOK Only)

If you use your own API key, it is stored securely in the device's Keychain — Apple's encrypted, hardware-backed credential storage. Your API key is never transmitted to our servers.

Face ID / Touch ID

If you enable app lock, authentication is handled entirely by iOS using Apple's LocalAuthentication framework. Tephra never accesses, stores, or transmits your biometric data. Your Face ID or Touch ID data remains in the device's Secure Enclave and is never available to any app — including Tephra.

Where Your Notes Are Stored

Notes are stored as plain Markdown files in a folder you choose — your Obsidian vault, or on your iPhone. They live only where you save them: Tephra has no server that stores your note content, and we have no access to your files.

Device-Level Data Protection

All notes stored on your device are encrypted at rest by iOS Data Protection. When your device is locked, note files are protected by hardware encryption tied to your passcode. This encryption is automatic and requires no setup from you.

If you enable the optional Face ID / Touch ID app lock in Settings → Privacy & Security → Lock with Face ID, Tephra requires biometric authentication (or your device passcode as a fallback) each time you return to the app. This adds an additional layer of protection beyond the device lock screen.

No tracking. No analytics. No ads. No third-party SDKs that collect data. No account required to use the app.

Data Retention

Audio recordings are deleted as soon as the note they produced is saved — and, if processing fails, once you retry or dismiss the recording. They are never uploaded. Notes persist in your chosen storage location until you delete them. We do not maintain server-side copies of your notes; Pro formatting requests pass through our server in memory only and are not stored.

Data Controller

The controller responsible for the limited data processing described in this policy is the operator identified in our Impressum. You can reach us at hello@tephra.app.

Legal Basis for Processing

Where the GDPR applies, we rely on the following legal bases: performing our contract with you to provide the features you request, such as transcription and AI formatting (Art. 6(1)(b) GDPR); your consent for optional device permissions such as microphone and location, which you can withdraw at any time in your device settings (Art. 6(1)(a) GDPR); and our legitimate interest in operating the service securely, for example rate-limiting and abuse prevention (Art. 6(1)(f) GDPR).

International Transfers

To format a note, the text is sent to the AI provider you use (OpenAI, Google, Anthropic, or Groq), which may process it on servers outside the European Economic Area, including the United States. Such transfers rely on the provider's applicable safeguards, such as the EU Standard Contractual Clauses. With Bring Your Own Key you select the provider directly and your text does not pass through our servers.

Your Rights

Because we keep no server-side copy of your notes and require no account, most of your data stays under your direct control: you can edit or delete any note at any time, and uninstalling the app removes its local data. Where the GDPR applies, you also have the right to access, rectify, erase, restrict, and port your personal data, to object to processing, and to withdraw any consent you have given. You may also lodge a complaint with a data-protection supervisory authority. To exercise these rights, contact us at hello@tephra.app.

Children's Privacy

Tephra is not directed at children under the age of 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, please contact us so we can take appropriate action.

Changes to This Policy

If we make changes to this Privacy Policy, we will update the "Last updated" date at the top of this page. We encourage you to review this policy periodically for any changes.

Contact Us

If you have questions or concerns about this Privacy Policy or our data practices, please reach out.

Email us at

hello@tephra.app