YOUR WORDS. YOUR CHOICES.
Privacy
What stays on your device, what reaches your account, and the choices you can make. This page covers Ear Prompter for iPhone and iPad and the earprompter.app website.
Updated 25 September 2026
Who we are
Ear Prompter is built to help you find confidence in your voice and make every delivery your own. We aim to make the way your information is handled just as clear as the words you want to share. The app uses TellyPrompter’s shared account service.
Aldgate Tower, 2 Leman St, London E1 8FA.
For privacy questions or requests, get in touch with us.
The TellyPrompter browser app has its own privacy information. Its recording, speech and analytics features differ from the native Ear Prompter app described here.
Your scripts and account sync
The app saves scripts and working drafts on your device. You can use the local library without an account. A free account does not sync scripts from the iOS app.
When you sign in with Pro, script sync can send script text and library information to your account. Sync runs after sign-in, after changes to the library and when you return to the app; you can also request it from your account. Synced scripts use the shared TellyPrompter account service, hosted with Supabase.
Pro sync means the text of synced scripts leaves your device. It does not upload your rehearsal audio or recorded takes. Turning off usage sharing does not turn off script sync: these are separate functions.
Your voice and device permissions
Ear Prompter uses Apple’s on-device speech recognition to follow your place in a script. The app does not send your audio to a remote speech service. If a supported language needs additional resources, those are downloaded from Apple.
Microphone access lets you record a read or take and follow your voice. Camera access is needed for video takes. Saving to Photos requires permission to add the recording. You can review and change these permissions in your device’s Settings.
Reads, takes and device backups
Your rehearsal reads and audio or video takes are saved in the app’s storage on your device. Ear Prompter does not sync these media files to its account service. Share, Save to Files and Save to Photos send a copy to the destination you choose; that destination’s storage and privacy settings then apply.
Your device backup is a separate copy. Scripts, drafts, reads and takes may be included in an iCloud or computer backup, depending on your device’s backup settings. The app does not exclude these files from backup. This is your device backup, not an Ear Prompter account recording service. Read Apple’s explanation of iCloud Backup.
Manage backups through Apple’s settings. Deleting something in Ear Prompter does not remove copies you have exported, shared or previously backed up. Save an independent copy of any take you need to keep; free-plan storage limits can remove older takes.
Sign-in and purchases
If you create an account, we process your email address and an account identifier to sign you in and provide account features. You can sign in with Apple, Google or an email code. If you choose Apple’s Hide My Email, the address supplied to us can be an Apple relay address.
App Store purchases are handled by Apple. The app sends signed transaction information, and renewal information when available, to our account service to verify and restore your Pro access. This connects your purchase entitlement to your signed-in account. We do not receive your full payment-card details from an App Store purchase.
Apple also sends our service verified purchase, renewal and refund notifications when the app is closed. We send limited billing events to PostHog’s EU service to report these outcomes: product category, transaction date, notification type, test or production status, and price and currency when available. These events do not include your account or Apple transaction identifiers and are not linked to an analytics profile. This server-side billing reporting operates independently of the app’s usage-sharing and screen-replay switches.
Optional usage data in the app
Share usage data is on by default. You can turn it off under Settings. It controls device product analytics and take-performance reports; switching it off clears queued analytics, resets the app’s analytics identifier and also turns off optional screen replay.
Product analytics help us understand which screens and steps are used. They use a random identifier created by the app, rather than your account ID or an advertising identifier. Events contain limited technical details, codes and counts. They do not contain script text, transcripts or recordings. They include selected operational outcomes such as sign-in, script saving, sync, purchases and take quality, plus counts of crashes and hangs delivered by Apple’s diagnostic framework. They are sent to PostHog, our analytics provider, through its EU endpoint.
When you finish a take while signed in with usage sharing on, the app can send a separate report to our service: matching counts and the positions and timings of the guide’s pauses and movements. These reports are linked to your account, but contain neither recognised words nor the script text.
Optional masked screen replay in the app
In app versions that offer Share masked screen replay under Settings → Usage, masked replay is on by default while usage sharing is on, unless you have previously turned it off. You can turn it off at any time using this switch. When enabled, PostHog receives a masked visual replay of the app through its EU service, so we can understand navigation and investigate problems. Older app versions without this switch do not record replay.
Masking happens on the device before transmission. Text and images are hidden. Script and performance screens, account details, camera previews and recorded-video playback are explicitly masked. Replay does not record your microphone, voice or take audio. We disable automatic interaction-text capture, network-detail capture and console-log capture. Recordings use the app’s random analytics identifier, not your account ID.
You can turn replay off at any time. Turning off Share usage data also turns replay off; turning usage sharing back on does not turn replay back on. Stopping replay clears its queued data and prevents future capture. A request already sent cannot be recalled, and recordings already received are not deleted by the switch. Contact us to request earlier erasure.
Analytics on this website
The homepage measures visits and clicks on its App Store link through PostHog. The Support, Privacy and Terms pages let you change your analytics preference but do not send these analytics events. Analytics is on by default. Use Analytics settings in the footer to turn it off. This website choice is separate from the app’s Share usage data setting.
Events include a random identifier for the current page visit, a broad screen-size category and a broad referral category such as a search engine or a direct visit. Recognised advertising links also include a fixed campaign category, so we can distinguish campaign visits and App Store clicks. The identifier is held in memory and changes on a new page load. We do not send raw referring addresses, query strings, account details or persistent visitor identifiers in these events, and we do not record sessions.
The analytics service receives the network request needed to deliver an event. The event settings disable location enrichment and person profiles. For recognised campaign visits with website analytics on, the App Store link includes an Apple campaign code for aggregate campaign reporting. Turning website analytics off removes that code from the link. This site respects Global Privacy Control and Do Not Track, and excludes local development, previews and marked internal traffic. Your on/off choice is remembered in this browser’s local storage.
Diagnostics and support
The app keeps a local diagnostics log of technical events, timings, counts and settings. To send a support report, open Settings → About → Report a problem. You can review the message and diagnostic attachment before sending. The attachment includes technical details, not your scripts, voice or video.
If you allow Apple to share crash information with developers, we may receive crash reports through Apple. Apple controls that sharing setting. If you contact us, we receive your message, contact address and any information or files you choose to include so we can help with your request.
Signing out and deleting data
Signing out leaves your scripts, reads and takes on the device. Nothing is removed or hidden at sign-out. Keep this in mind if someone else uses the same device.
To delete your account, open Settings → Account → Delete account. Account deletion removes account-held information, including synced scripts and account-linked take reports. Local scripts, reads and takes remain on the device; manage them in the app separately.
Account deletion does not cancel an Apple subscription, delete exports or remove your device backups. Manage a subscription through Apple and backups through your device settings. Previously sent product analytics are separate from your account: contact us if you want to request erasure. Records required for accounting or other legal obligations may need to be retained.
How long information is kept
Your account email and identifier are kept until account deletion. Synced scripts stay in the account until you delete them or the account; a deletion marker lets the change reach your other devices. Account-linked take-performance reports are kept with the account and removed when it is deleted.
Product analytics events are retained for seven years under the shared service’s published retention policy. Deleting your account does not automatically erase these separate event records. You can contact us to request earlier erasure. Optional masked app replays are retained for 30 days under the current recording setting. This website does not create session replays.
Copies on your device, in exports and in your device backups are controlled separately. App storage limits can remove older free-plan takes; backup and export retention depends on the destination you use. Accounting records that must be kept by law are retained for the required period.
Your privacy choices and rights
You can ask to access, correct or erase personal data we hold about you. Depending on the circumstances, you may also have rights to restrict its use, receive a portable copy or object to processing. You can change the usage-sharing choices described above at any time.
You can object to the use of your personal data. Send privacy requests to contact@tellyprompter.com. We may need information to identify the relevant records and verify your request.
You can also raise a concern with the UK Information Commissioner’s Office or your local data-protection authority. When we change this page, we update the date shown above.