Tally collects what it needs to run a budgeting service and nothing more: your account details (email address, a bcrypt-hashed password, or a sign-in token from Apple or Google); the financial data you enter or import (transactions, amounts, dates, categories, budgets, income, recurring bills and net-worth entries); a device token for push notifications, if you turn them on; and optional profile details (display name, username, avatar colour). If you link a bank or Apple Wallet, Tally receives account names, balances and transactions from Plaid or Apple as described in section 3. Tally does not collect advertising identifiers and contains no third-party advertising or analytics SDKs. If part of the app fails, Tally may send a technical error report to Tally's own server: what failed, the app version, your iOS version and your device model. These reports never include transactions, amounts, balances, merchant names, account names or your email address, they go to no third party, and they are not used to build a profile of you or to track you. You can turn them off at any time in Settings → Security & Privacy → Share Diagnostics.
Usage events. Tally also records how the app itself is used and sends it to Tally's own server, linked to your account: which screens and setup steps you reached; the choices you made in setup, such as how often you are paid (never how much); which offers you were shown and what you chose; whether a bank connection finished; which of Tally's messages and notifications reached you and what you did with them; and how long setup and its screens took, kept only as a rough band such as "under 30 seconds", never to the second. If you use the subscription check during setup, the size of what you picked is kept as one of four bands (none, low, mid or high), never as an amount. Each event carries the app version and the time it happened. Usage events never include an amount, a balance, a merchant name, an account name or anything you typed; they go to no third party, and they are not used for advertising or to track you across other companies' apps or websites. We use them to count how many people reach each step, so we can see where Tally is hard to use. They are kept while your account is open and deleted when you delete your account. They are on until you switch them off, which you can do at any time in Settings → Security & Privacy → Share Usage; from then on nothing more is sent.
Your information is used only to operate Tally: to show your budgets, transactions and insights; to sync your linked accounts; to send the notifications you opted into; to run family sharing when you turn it on; to answer your support requests; and, through the usage events described in section 1, to see where Tally is hard to use so we can improve it. Your personal and financial data is never sold and never used for advertising or marketing — by law, under this policy, and by construction: there is no third-party advertising, analytics or tracking code in Tally, and no advertising identifier is ever requested.
Plaid (US banks). You sign in to your bank on Plaid's screen. Your bank username and password never reach Tally. Plaid returns account names, balances and transactions, read-only; Tally has no ability to move money, make payments or change anything at your bank. The access token that lets Tally read this data is stored encrypted with AES-256-GCM on our server. Plaid's handling of your data is described at plaid.com/how-we-handle-data and plaid.com/legal.
Apple Wallet (Apple Card and Apple Cash). With your permission, Tally reads transactions and balances from Apple Wallet on your device through Apple's FinanceKit. They are stored on Tally's server like bank transactions so your budgets, insights and family sharing work with them. You can revoke this at any time in iOS Settings → Privacy & Security → Wallet.
Lean Technologies (UAE banks). Lean bank linking is in testing (sandbox) and is not yet generally available. When it is, it works the same way: you sign in on Lean's screen, Tally receives read-only account and transaction data, and Lean's privacy policy (lean.tech/privacy) governs Lean's handling of it.
Everything between the app and Tally's server travels over HTTPS (TLS 1.2 or newer, enforced by iOS App Transport Security). Your session token is stored in the iOS Keychain. Passwords are hashed with bcrypt (cost 12) and never stored in plain text; password-reset codes are stored hashed and expire after 15 minutes. Bank access tokens are encrypted with AES-256-GCM before they are stored. Your data is kept in a database hosted by Railway, which states that its storage is encrypted at rest. Every request to our server is checked against your signed session token and scoped to your account. Inside the app you can add Face ID or Touch ID lock, lock on background, auto-lock and Hide Amounts in Settings → Security & Privacy. No system is perfectly secure and we do not claim otherwise; if you find a problem, please tell us at tallysupportline@gmail.com.
Tally AI answers questions about your money. When — and only when — you send it a question, the app builds a summary of your spending (totals, budgets, top merchants, account balances and this month's transactions) and sends it, with your question, through Tally's server to our AI provider, DeepSeek, to generate the answer. It is sent to our AI provider to generate the answer and not used by Tally for any other purpose. Nothing is sent to the AI provider unless you ask a question. DeepSeek's handling of data is governed by its own privacy policy.
Tally uses these services, each governed by its own privacy policy: Plaid Inc. (plaid.com/legal) for US bank connections; Apple FinanceKit (Apple Wallet) for Apple Card and Apple Cash; Lean Technologies (lean.tech/privacy) for UAE bank connections, currently in testing; Sign in with Apple (apple.com/legal/privacy) and Google Sign-In (policies.google.com/privacy), whose sign-in tokens we verify on our server against Apple's and Google's public keys; Apple's StoreKit for Tally Pro subscriptions; the Apple Push Notification service for notifications you opt into; Resend (resend.com) for transactional email such as password-reset codes; Railway (railway.com) for hosting; and DeepSeek (deepseek.com) for Tally AI answers, only when you ask. Tally is not responsible for the privacy practices of these services.
You, through the app. The people you choose, through family sharing, which is opt-in: you decide whether to share transactions, budgets and income, you can mark any transaction private, and account balances are never shared with family members. There is no screen, tool or report anywhere in Tally that shows one person's transactions to anyone but them and the people they have chosen to share with. Error reports are stripped of amounts and merchant names before they are sent, and the usage events described in section 1 never contain them. Access to the systems that store your data is restricted to authorised personnel who need it to operate, support and secure the service, and is never used for marketing.
Your data is kept for as long as your account is active. You can disconnect a bank at any time in Bank Sync, which revokes that connection at Plaid. You can delete your account at any time in Settings → Delete Account. Deletion revokes Tally's bank connections at Plaid, removes your Apple Wallet data from our server, and deletes your transactions, budgets, notifications, usage events, family memberships and account. Upon account deletion your data is removed from our systems; our hosting provider's backups expire on their own schedule.
Tally is not intended for use by children under the age of 13. We do not knowingly collect personal information from children. If we become aware that a child under 13 has provided us with personal data, we will take steps to delete such information promptly.
You can see all of your data in the app, correct it, export it (CSV from Settings → Data, and The Money Book PDF from More), disconnect banks, revoke Apple Wallet access in iOS Settings, and delete your account. Depending on where you live you may have further rights under local law, including the right to withdraw consent; write to us at the address below and we will help.
Who is responsible for your data. Tally is operated by Abderrahman Belfakih, in the United States, who is the data controller for the purposes of the UK and EU General Data Protection Regulation. You can reach us at any time at tallysupportline@gmail.com.
Why we are allowed to hold it. Most of what Tally stores is held because you asked for a budgeting service and we cannot provide one without it — your account, your transactions, your budgets, and the family or group sharing you switched on (Article 6(1)(b), performance of a contract). Some things are held only on your separate, opt-in consent, and you can withdraw any of them at any time without losing the rest: linking a bank, connecting Apple Wallet, push notifications and asking Tally AI a question (Article 6(1)(a)). Keeping the service secure and available — rate limiting, abuse prevention, error monitoring — and learning from the usage events described in section 1 where Tally is hard to use rest on our legitimate interest in running a safe service that works (Article 6(1)(f)), balanced against your privacy by stripping amounts, merchant names, account names and email addresses out of every error report before it is stored, and by never putting them in a usage event. You can object at any time: the Share Diagnostics and Share Usage switches in Settings → Security & Privacy stop the app sending either.
Sensitive details inside bank transactions. A transaction description written by your bank can reveal things the law treats as special — a pharmacy, a clinic, a place of worship, a political donation, a union. Tally does not look for this, does not categorise on it, does not profile you with it, and never shares it. But when you connect a bank you are asking Tally to store the descriptions your bank sends, and that is your explicit consent to do so (Article 9(2)(a)). You can edit any description, mark any transaction private so it is never shared, delete any transaction, or disconnect the bank entirely.
Where your data is, and why that is lawful. Tally's server and database are hosted in the United States. Sending your data there is necessary to perform the contract you entered into with us, and where you connect a bank or use an optional feature you have given explicit consent knowing the transfer takes place (Article 49(1)(a) and (b)). The third parties who may process your data on our behalf are named in section 6, and none of them receives it for their own purposes.
How long we keep it. Your financial data, and the usage events described in section 1, are kept while your account is open and deleted when you delete your account, as described in section 8. Everything else runs on a fixed schedule that is enforced automatically, not by memory: password-reset codes expire in 15 minutes, sign-in codes in 10, trusted devices after 90 days, sessions after 30 days, bank sync records after 90 days, and technical error reports after 90 days at the outside — sooner once resolved. An hourly job deletes anything past its date.
Your rights. You have the right to ask for a copy of your data, to correct it, to have it erased, to restrict or object to how it is used, to receive it in a portable format, and to withdraw any consent you gave. Most of these you can exercise yourself inside the app immediately: everything is visible on screen, editable, exportable as CSV from Settings → Data and as a PDF report from More, and erasable from Settings → Delete Account. For anything else, write to tallysupportline@gmail.com from the address on your account and we will answer within one month. You also have the right to complain to your national data protection authority — in the United Kingdom, the Information Commissioner's Office.
No automated decisions about you. Tally does not make any decision about you by automated means that produces a legal effect or anything similarly significant. Categories, insights, scores and forecasts are suggestions shown to you, based on your own data, that you can change or ignore.
Bank connections in Europe. Tally does not currently connect to European banks. A European user adds transactions manually or imports a file exported from their bank. If that changes, the licensed provider will be named in this policy before the first European bank is connected.
The website at tallybudget.link is separate from the app, and it counts visits so we can tell whether anyone is finding it. There are no cookies, no advertising or analytics products, and nothing is stored on your device. Cloudflare, which serves the site, passes on the country a request came from and turns the address into a number using today's date and a secret Tally holds. That number changes every day and cannot be turned back into an address; the address itself is never sent on and never stored. What is kept is the page, the country, the language the browser asked for, whether the screen is a phone's or a computer's, where the visit came from (a search engine, a social app, an AI assistant, or a link we handed out), how long the page was read and how far down it was read. None of it is tied to a Tally account, and nobody can be identified from it. Search engines stopped telling websites what people typed years ago, and Tally makes no attempt to find out by other means.
We may update this Privacy Policy from time to time. We will notify you of material changes through the app or via email. Your continued use of Tally after such changes constitutes acceptance of the updated policy.
For privacy-related inquiries, please contact us at tallysupportline@gmail.com.
Last updated: September 23, 2026