Talekeep — Privacy Policy
Last updated: 8 June 2026
The short version
Talekeep is a local-first app. Your conversations are archived
on your own Mac, in a location you choose,
encrypted with a key only you control. We operate no servers and
never receive your messages. There is no Talekeep account and no telemetry.
What Talekeep stores, and where
- Your archived conversations — messages you choose to sync from a
connected account (currently Telegram), including message text, sender identifiers,
timestamps, and media metadata. Message body text is encrypted at rest
(AES-GCM); metadata (titles, dates, kinds) is stored in plaintext so the archive is
searchable.
- Location — the default is inside the app's sandbox container; you
may move it to any folder you choose. The archive never leaves your device unless
you copy it.
- Credentials — your Telegram
api_id/api_hash
are stored in the macOS Keychain and are sent only to Telegram, never
to us.
- Encryption keys — managed by you via a security level
(Keychain-protected or passphrase-protected) plus a recovery code you save yourself.
About other people's messages
A conversation archive necessarily contains messages other people sent
to you. Talekeep treats this as your own copy of your own conversations
(the same basis on which Telegram/WhatsApp/standard backup tools operate). You are
responsible for handling this data lawfully in your jurisdiction. Talekeep does not build
profiles, does not aggregate across users, and does not transmit this data anywhere.
What Talekeep does NOT do
- No Talekeep servers; no cloud sync; no account.
- No analytics, ads, tracking, or telemetry.
- No selling or sharing of your data.
AI features and data sharing
- On-device AI ("Ask AI") — by default, answers are generated
on your Mac using Apple's on-device model. Your messages are
not sent anywhere.
- Cloud AI — optional, OFF by default, bring-your-own-key. In
Settings → AI you may choose to use a third-party cloud model (any
OpenAI-compatible provider) with your own API key. When you turn this
on, "Ask AI" transmits the relevant messages to the provider you configured
so it can answer. This is your own integration with your key: Talekeep
runs no AI service and never receives this data; how the provider handles it is governed
by their terms. The app clearly shows, while the option is on, that your
messages leave your Mac.
- MCP server — optional, OFF by default. In
Settings → AI access (MCP) you may start a local, read-only
server on
127.0.0.1 (localhost only — not reachable off this machine) that
lets an MCP client you connect (e.g. a desktop AI app) query your archive on this Mac. If
the client you connect is itself a cloud AI, what it does with the data it reads is
governed by that client/provider's terms; enabling the server and
connecting such a client is your choice.
Security
- Message bodies encrypted with AES-GCM (CryptoKit).
- Passphrase level derives the key with PBKDF2-HMAC-SHA256 (work-factored).
- You hold a recovery code; if you choose passphrase level and lose both the
passphrase and the recovery code, the archive is unrecoverable — by design,
because the key is never escrowed to anyone.
Your control and rights
- Access/export — it's your local file; you can open, copy, or move it.
- Deletion — remove a conversation, remove an account (deletes its
data), or delete the library folder. Deletion is local and immediate.
- Depending on your jurisdiction (e.g. GDPR/CCPA) you may have additional rights
regarding personal data; because Talekeep stores everything locally and we hold none of
your data, you exercise these directly on your device.
Children
Talekeep is not directed at children and stores only conversations you choose to archive
from your own accounts.
Changes & contact
We may update this policy; material changes will be noted in-app / in release notes.
Contact: enquiry@craveva.com