Security

The part of Tellstack that really sits in the open is your form. So that comes first: what happens to a submission, how spam is scored — and why none of it quietly disappears.

When someone submits your form

Spam is scored, not discarded
Anything suspicious gets a score and lands in the spam folder — reasons attached, one click back to the inbox. Real feedback must not be lost because a rule got it wrong.
No captcha
Your users solve no puzzles and click no traffic lights. The hurdle for a human is zero — it sits in what they write, not in front of it.
No IP address in the database
What is stored is a one-way value derived from an IP hash and the browser string. Enough to spot bursts and word-for-word repeats, impossible to turn back into an address.
No third party, no fingerprinting
No submission is sent anywhere to be judged. Every signal comes from the text itself and from what already sits in your workspace.
What gets noticed
Links and sales copy, the same message twice within a day, bursts from one sender, throwaway addresses, all-caps shouting — each signal weak on its own, only the sum decides.
The threshold is yours
You set the score at which something is filtered. A single signal is never enough on its own — unless you blocked that address or domain yourself.
Block lists only grow on a click
Mark something as spam by hand and you are offered to block the sender. Nothing is blocked until you agree. A list that grows quietly ends up eating real feedback.
Spam costs you nothing
Filtered submissions do not count against your monthly allowance, trigger no webhook, and are never sent through the AI layer.
The bot trap
A field no human ever sees. If it is filled in, no human was there — the one place where a submission ends without being filed.
Timing only applies to hosted forms
A script is faster than any typist. Timing comes from a signed stamp in the form; your own app and the REST API are never penalised for it.
Limits on a submission
Every public input passes a schema: type, length, allowed values, a 64 KB ceiling. Plus rate limits per form, per key and per sender.
Project keys only write
A public key can create feedback and nothing else. There is no endpoint that hands anything back for such a key.
Targets are checked, not trusted
The redirect after submitting and every image address must be a complete http(s) URL. Script and data URLs do not get through.
Nothing is rendered raw
Whatever someone writes is escaped when displayed — in the inbox as well as in the notification email. User text is never executed as HTML.
A test stays a test
Test submissions from the form editor live in their own folder: no allowance, no analysis, in no metric.

And around your account

Sign-in
Passkeys (WebAuthn). No password, no password store, several passkeys per account.
Sessions
Access token valid for 15 minutes, HttpOnly and Secure. The refresh session rotates on every use and can be ended individually or for all devices.
Workspace boundary
Every query additionally filters on the workspace ID. An ID from the client never counts as permission.
Location
Application, database and backups run on a server in Germany (Nuremberg data centre).

Limits worth knowing about

  • No spam detection is always right. That is why submissions are scored rather than blocked: what gets filtered sits in the spam folder and stays reachable instead of vanishing. Look in now and then.
  • The only way back into an account is a recovery code. There is no second route — not even through us. So register several passkeys and keep the codes somewhere else.
  • The export covers your feedback, not the whole account. Submissions can be downloaded as CSV or JSON at any time. A subject access request under Art. 15 GDPR is handled by hand.
  • Destructive steps need no second approval. An owner can delete a project or an empty workspace alone. Hand out the owner role sparingly — feedback itself is always kept, though.

This list is here because a security page without open points is not credible. It names no plans, only what holds today.

Frequently asked questions

Do I have to put a captcha in front of my users?

No. Tellstack deliberately uses none. A submission is judged by its content and its behaviour, not by whether someone solves a puzzle — that costs real users patience and stops barely any script.

What happens to feedback flagged as spam?

It lands in the spam folder with its score and reasons, and one click brings it back. Nothing is deleted there unless you trigger it yourself — there is no cron job and no deadline that clears your data away.

Does Tellstack store the sender's IP address?

No. The IP and browser string become a one-way value that makes bursts and repeats visible. The address itself is not stored and cannot be recovered from it.

Can a project key read data?

No. Public project keys can only write feedback. There is no endpoint that returns anything for such a key.

Does Tellstack store passwords?

No. Sign-in runs entirely on passkeys (WebAuthn). There is no password database, so there is nothing to steal in a breach.

Where is my data stored?

On a server in Germany (Nuremberg data centre), together with the backups. Payment, email delivery and — only on plans with the AI layer — the analysis run through individual providers; the privacy notice names them and their purpose.

Does Tellstack use tracking or advertising cookies?

No. There is no analytics script, no advertising cookies and no session recording. Only the cookies technically required for sign-in are set.

Found a hole?

Reports of security holes are welcome and will not be answered with lawyers. Please use the address given in the privacy notice and give us time to fix it before it goes public.