Skip to main content
Comparison

Where Does Your Text Go? A Data-Flow Audit of 11 iPhone TTS Apps

Local TTS12 min

If a text-to-speech app makes its voices on a server, your text is uploaded — that is the mechanism, not a scandal. What eleven iPhone TTS apps say about where your words end up, in their own labels, policies, and terms.

Your text follows the voice. That is the entire answer, and the rest of this article is the receipts. If a text-to-speech app generates its voices on a server, the text you paste is uploaded — not as a data grab, but because that is literally how the speech gets made. If the voices are generated on the phone, nothing needs to leave. Every other privacy question about this category is downstream of that one fact.

It matters because of what people actually feed these apps. Somewhere on your phone is a document you would not read aloud on a crowded train: a lease with your salary in it, a medical letter, an offer you have not accepted yet. Text-to-speech exists for exactly these documents — long, dense, important — and almost nobody asks where the text goes before pressing play.

The awkward part: you cannot reliably tell the two kinds of app apart from the App Store privacy label. Of the four server-based apps in this audit, three carry labels that never mention your text at all.

Scope and sources: This article audits eleven iPhone apps: Local TTS, SpeakCove, PageEcho, VoiceReader AI, Speech Central, Voice Dream, ElevenReader, Speechify, NaturalReader, Listening, and TTSReader — plus Apple’s built-in Spoken Content. Local TTS is our own app, so nothing here rests on our opinion: every claim is quoted from each product’s own US App Store privacy label, privacy policy, terms of service, or help documentation, with links so you can check the source. Everything was read on August 25, 2026. This is a documentation audit, not a packet capture — it reports what each vendor has put on the record.

Two architectures, one consequence

Every app in this category is built one of two ways.

Server synthesis. Your text travels to a data center, a large model turns it into audio, and the audio streams back. The upside is real: models that size sound better than anything that fits in a phone. The consequence is also real: your document is now on someone else’s computer, covered by their retention schedule, their terms, and their subprocessors. None of that is hidden — it is usually written down quite plainly, just not on the store page.

On-device synthesis. A compact neural model runs on the iPhone itself. The audio quality race is closer than it used to be, and the data-flow question simply evaporates: there is no server to send text to. Privacy is not a policy here; it is an architecture.

This is the same split we measured from the other direction in our airplane-mode audit: an app that can read brand-new text with the network off is, necessarily, an app that does not need your text. The offline question and the privacy question are the same question.

What eleven apps put on the record

Labels are from each app’s US App Store page; quotes are from the linked vendor documents. All read on August 25, 2026.

AppWhere speech is madeUS privacy labelYour text, in their own wordsAccount
Local TTSOn your iPhone“Data Not Collected”“No internet, no account, and no tracking. Nothing ever leaves your device.”No
SpeakCoveOn your iPhone“Data Not Collected”“Your text never leaves your iPhone.” (policy)No
PageEchoOn your iPhone“Data Not Collected”“Processed entirely on your device and… not sent to the cloud.” (policy)No
VoiceReader AIOn your iPhone“Data Not Collected”“No text is sent to the Internet, no external servers.” (policy)No
Speech CentralOn your iPhone (Apple voices); optional cloud voices via your own API keys“Data Not Collected”“Never sent to our servers.” (policy)No
Voice DreamOn your iPhone — “All voices work offline”Tracks User ID, Device ID, and advertising dataIts privacy policy never mentions documents or reading content at allYes — “a subscription is required”
Apple Spoken ContentOn your iPhone, with downloaded system voices— (built into iOS)Apple publishes no explicit data-flow statement for this featureNo
ElevenReaderOn ElevenLabs’ serversEmail, name, and User ID linked to you; no “User Content” entryMay be processed to “train and/or otherwise improve our AI models” (policy)Yes
SpeechifyOn servers; on-device voices offered as an option since Dec 2025Tracks identifiers; no “User Content” entrySaved content is “synced with our servers”; terms: “not considered to be confidential” (policy)Yes
NaturalReaderOn servers — text flows to Google, Microsoft, ElevenLabs, OpenAI, and AWS (list)Tracks identifiers; no “User Content” entryDocuments kept up to two years; generated audio 360 days; “does not use customer-provided content… to train” AI modelsYes — registration “may be required”
ListeningOn its servers — “Uploads to Listening”“User Content” linked to your identityLicense to “host, store, transfer… modify for the purpose of formatting for audio” (terms)Yes — “you must register”
TTSReader— iOS app unmaintained since January 2020“No Details Provided”Web policy: MP3 exports are “stored on our server and are publicly accessible to anyone with the link” (policy)No

Read down the second column and the table sorts itself. Six of these options synthesize on the phone, and their vendors say so in blunt, checkable sentences. Four synthesize on servers, and their own paperwork — never the store page — describes uploads, retention windows, and content licenses. One is abandoned.

“Is Speechify private?” — answered from its own documents

This is the question people actually type into search bars, so it deserves a direct answer rather than a vibe.

If “private” means my documents stay on my phone, then no — and Speechify’s own privacy policy says so without any prompting from us: “User Content you save will be stored locally on that device and synced with our servers,” and “Information submitted to Speechify will be transferred to, processed, and stored in the United States.” Its Terms of Service go further than most people expect: “User Material is not considered to be confidential. You agree not to submit any content as User Material in which you have any expectation of privacy.” The App Store label adds that identifiers are used for tracking across other companies’ apps.

Two things in Speechify’s favor, because an audit that only collects unflattering quotes is a hit piece. First, all of the above is published openly — you are reading their disclosures, not a leak. Second, in December 2025 Speechify launched on-device iOS voices: “Users can choose between cloud-based voices or on-device playback depending on their environment, preferences, and connectivity needs.” The default architecture is still the server, but the company itself now treats on-device as the direction of travel.

If you are weighing the two side by side, we keep a sourced, dated comparison — prices and claims linked to the originals, including where Speechify is stronger.

The label that never mentions your text

Here is the finding we did not expect when we started pulling App Store pages.

Apple’s privacy label has a data type designed for exactly this category: “User Content.” It is how an app declares that it handles the things you create and import — documents, messages, photos. Now look at who declares it. Speechify’s label: no User Content entry, anywhere. NaturalReader’s label: none. ElevenReader’s label: none — this for an app whose entire function is uploading your reading material to a server that reads it back.

The only server-based app in this audit whose label declares User Content linked to your identity is Listening. Whatever else you make of its data practices, its label is the one that matches its policy.

Two caveats keep this honest. The labels are self-reported, and every one of them carries Apple’s own disclaimer: the information “has not been verified by Apple.” And the label’s definitions leave developers genuine wiggle room about what counts as “collected.” That is precisely the problem. The one document shoppers actually see was silent about user text in three cases out of four — which is why the policy, not the label, is where this article gets its facts.

Voice Dream deserves its own footnote here. Its store listing makes the offline claim plainly — “All voices work offline and play in the background” — and its OCR scanner “works entirely on device.” But its privacy label declares tracking with advertising data, and its privacy policy is a generic template that never once mentions documents or reading content. The engine is local; the paperwork around it tells you nothing either way. It also gates everything behind a subscription: “a subscription is required to access the app.”

Who may train on your words

Three vendors answer the AI-training question in writing, and they answer it three different ways.

ElevenLabs says yes, with an opt-out. Its privacy policy states: “We may process your Personal Data to research, develop, train and/or otherwise improve our AI models,” where the processed data explicitly includes text. There is an opt-out in the account’s “Data use” menu — but it “will only apply with respect to Personal Data provided or made available following the submission of the opt-out.” Nothing you submitted before flipping the switch is covered. The ElevenReader terms also take a license to use your uploads “to improve the Services, and to develop new services and products.” ElevenLabs does offer a Zero Retention Mode — for enterprise API customers only; its own documentation states it “applies to API use only,” so nothing in the consumer Reader app is covered.

NaturalReader says no, flatly. Its policy states: “NaturalSoft does not use customer-provided content or generated output to train NaturalSoft or third-party AI models,” and its subprocessor list adds that it “does not authorize these providers to use Customer Content for AI model training.” Credit where due: NaturalReader also publishes the most transparent paperwork in this audit — a retention table with actual numbers (documents up to two years, unregistered uploads up to 36 hours, generated audio 360 days) and a public list naming exactly which clouds receive your text. Your documents do the most traveling here, but no vendor tells you more precisely where.

Speechify sits in between. Its policy says employees do not ordinarily view your content, but it may be viewed “to improve our algorithms.” No opt-out is described.

Everyone else’s policy is silent on training — and the five on-device apps have nothing to be silent about, because an app that collects no text cannot train on it.

The app Apple never explains

Apple’s built-in Spoken Content (Settings → Accessibility) is the one option here with no App Store label at all, and its data flow is — surprisingly — undocumented. Apple’s support pages confirm the mechanics point the right way: the voices are files, downloaded to the phone — “Enhanced-quality voices can be 100 MB or larger. Connect your device to Wi-Fi to download and install one of these voices.” But nowhere does Apple publish the sentence “Spoken Content is processed on-device.”

The absence stands out because Apple writes that sentence about its other speech features: Personal Voice “is created on your device to keep your information private and secure”; Live Captions are “on-device-generated.” Downloaded voice files strongly imply local synthesis, and we would bet on it — but this audit only reports what vendors state, so Spoken Content gets an asterisk instead of a checkmark.

How to check any TTS app in about a minute

The next app you evaluate will not be in this table. The method transfers:

  1. Scroll the App Store page to “App Privacy.” Look for two things: any “Data Used to Track You” section, and whether “User Content” appears anywhere. Remember what you now know about that second one — its absence proves nothing.
  2. Open the privacy policy and search four words: content, upload, retain, train. Five minutes of reading around those four words tells you more than the entire store page.
  3. Run the airplane-mode test. Turn on Airplane Mode, confirm Wi-Fi is off too, paste in a sentence the app has never seen, press play. This is the ground truth that no paperwork can fake in either direction: an app that speaks new text with no connection is generating it locally — your words had no way to leave. The full version of this test has the details.

Limits of this audit

  • Documentation is not a wiretap. We read what vendors publish; we did not capture network traffic. An app can behave better than its paperwork — or worse. The paperwork is simply what the vendor is accountable for.
  • Labels are self-reported and unverified by Apple, on every app including ours.
  • Policies move. Every quote here was read on August 25, 2026, and any of them can change next quarter. The links are there so you can reread the source, not trust our excerpt.
  • Server-side is a legitimate trade. Bigger models sound better, cloud libraries sync everywhere, and a vendor with a clear policy, real retention numbers, and a no-training clause is making an honest offer. The point of this audit is not that upload is evil — it is that upload should be a decision you make, not one made quietly for you.

Our answer to the same question

Local TTS is our app, so hold it to the standard this article just set — the documents, not the marketing.

The US App Store label reads “Data Not Collected” — the same strongest-possible label as the other on-device apps in the table, self-reported like all of them, and backed by architecture rather than restraint: speech is generated on the iPhone by Supertonic 3 and Kokoro-82M, OCR runs on-device, and there is no account because there is nothing an account would do. The one network path in the product is optional iCloud sync for your notes, which runs through your own Apple account — Apple’s infrastructure, your encryption, not our servers, and speech synthesis stays local either way. The honest limits: it is iPhone and iPad only, and a phone-sized model will not out-sing a data center.

Which brings us to the only call to action that fits a privacy audit: don’t believe us — make the claim falsifiable. Download Local TTS free, take the most sensitive document on your phone, turn on Airplane Mode, paste a paragraph, and press play. The free plan reads up to 500 characters per note without an account, which is exactly enough to run the test in this article against the app that is asking for your trust. If it speaks, your words never left. That is the whole pitch.

The one-line version

The label can be silent and the policy can be long, but the engine cannot lie: if an app reads brand-new text with the network off, your text never needed to go anywhere at all.

Turn any text into speech — offline

Local TTS reads PDFs, e-books, and articles aloud right on your iPhone — private, natural, and yours.

Download on the App Store