Legal
Privacy notice
Last updated 25 August 2026
This notice covers the hosted version of Teleprompt, operated by Biios (Pune, India). If you run your own instance, none of your data reaches us and this notice does not apply to it; Running your own explains what that involves.
The engineering detail behind all of this is in Privacy and data, which lists the exact tables and the exact browser storage keys.
What we collect
- Account information from your sign-in provider. Google or GitHub, whichever you use: your name, email address and profile image, plus the OAuth tokens needed to keep you signed in. We request only the scopes needed to read that basic profile and a verified email address.
- Content you create. The scripts you write, and the rooms you open (including the snapshot of the script a room is using and its playback state).
- Device labels. A readable platform string such as “iPhone · Safari”, and a random identifier generated in your browser, so the connected-devices list is meaningful. Neither is derived from your hardware.
- Ordinary server logs. Requests, timestamps and error traces, kept only as long as they are useful for keeping the service running.
What we do not collect
- No analytics, advertising identifiers, tag managers or third-party trackers.
- No audio or video reaches us, ever. Camera access is never requested at all. The microphone is requested in exactly one place (voice tracking, which only listens while you hold it on), and even then the audio goes to your browser’s own speech recognition, never to us: we receive no audio and store no transcript. See Privacy and data for exactly what each browser does with it.
- No use of your content for advertising, resale, or training any model.
Why we hold it
To provide the service you asked for: to identify your account, to show your scripts on your other device, and to let a session resume after a reload. That is the entire purpose, and we do not process this data for anything else.
Who processes it
- Google and GitHub, for authentication only, and only the one you sign in with.
- Supabase, the Postgres database and the realtime relay.
- Our hosting provider, serving the application.
- Public STUN servers, consulted while two of your devices look for a direct route. They observe IP addresses during connection setup and never see message content.
When your two devices establish a direct connection, the messages between them are encrypted end to end and reach none of the parties above.
How long
Scripts stay until you delete them or delete your account. Rooms close themselves after five quiet minutes, and their device records are deleted when they do. Deleting your account removes everything attached to it; the schema cascades from the user record, so nothing is left orphaned.
Your rights
You can access, correct, export or delete your data. Scripts and rooms can be deleted from inside the app at any time. For an export or full account deletion, get in touch through biios.in/contact using the email address on the account, and we will action it.
If you are in a jurisdiction with statutory data-protection rights, such as the UK or EU, those rights apply and this section does not limit them.
Cookies
One cookie: the Auth.js session cookie that keeps you signed in. It is strictly necessary, and there are no analytics or advertising cookies, which is why there is no consent banner.
Children
Teleprompt is not directed at children under 13, and we do not knowingly collect their data.
Changes
If this notice changes materially we will update the date above and note it in the repository’s history, which is public.
Contact
Biios, Pune, India: biios.in/contact.