Skip to content
Tally
Loading...

Privacy Policy

Last updated: August 21, 2026

Tally ("Tally", "we", "us") is a bill-tracking and balance-forecasting tool. This policy explains what information we collect, how we use it, and the choices you have. It applies to the Tally web application and to the optional features described below, including connecting an AI agent directly to your own Tally data.

Information we collect

  • Account information. When you sign up, our authentication provider (Auth0) shares your email address and a unique identifier with us so we can associate your data with your account.
  • Financial data you enter or sync. Bank account nicknames and institutions, recurring bill names/amounts/schedules, and one-off transactions - typed in directly by you, or, if you choose to connect a bank account, imported automatically via Stripe Financial Connections. When you connect an account, Stripe shares your transaction history (dates, amounts, and descriptions) and your account's current balance with us - never your account number, routing number, or banking credentials, and Tally never sees your bank login. The bank-reported balance is shown only as a cross-check next to Tally's own computed balance; it never feeds the forecast. You can disconnect a linked account at any time.
  • Usage data. Standard server logs (timestamps, IP address, request paths) generated by our hosting infrastructure for security and debugging purposes.

How we use this information

  • To provide the forecasting and bill-tracking features you use Tally for.
  • To authenticate you and keep your account secure.
  • To diagnose and fix technical problems.
  • To communicate with you about your account, if needed.

We do not sell your personal information, and we do not use it for advertising or share it with data brokers.

How your financial data is protected

The financial details you enter or sync - account names and institutions, bill names and amounts, transaction amounts and descriptions, bank-reported balances, income sources, and notes - are encrypted before they are stored in our database, using a key that exists only while you are signed in and using Tally. The key is derived from a secret attached to your login session by our authentication provider; it is never stored in our database.

In practical terms: someone with access to the database - including us, our database provider, or an attacker who obtained a copy or a backup - would see scrambled ciphertext in place of your financial information, not your numbers. Some structural information is not encrypted because the application needs it to organize your data: dates (when a transaction happened or a pay cycle started), how often a bill repeats, category labels, and your email address. That means the pattern of activity is visible in the database, but never the names, the amounts, or who the money went to.

One consequence to be aware of: because we cannot decrypt your data without your login session, we also cannot recover it if your login identity is ever permanently lost. This is deliberate - it is what keeps your financial details unreadable to everyone but you.

Category suggestions

Tally offers optional suggestions to help you label your bills and transactions by category (Housing, Utilities, Subscriptions, and so on). If you turn this on for an account (Settings - off by default), then when you confirm a category for a bill or merchant, we record an anonymized version of the merchant name - lowercased, with punctuation removed, run through a lightweight check that skips anything that looks like it might contain a name, address, or account number - alongside the category you chose, in a shared reference used to suggest categories to every Tally user.

We do not record your name, account number, transaction amounts, or anything else that could identify you or your household as part of this - only the anonymized merchant name and category. Contributions to this shared reference are aggregate and can't be linked back to your account. Turning the setting off stops future contributions; it doesn't affect contributions already made, since those were never linked to your identity in the first place.

Connecting an AI agent

Tally offers an optional way to connect an AI agent - Claude, or any other agent that supports the same open standard - directly to your own Tally data: bills, transactions, forecasts, past pay cycles, budget insights, and your category spending report. Nothing connects until you deliberately set this up (Settings - "AI agent access") and sign in through the same secure login Tally's web app already uses.

A connected agent gets read-only access to your own data only - it can never create, change, or delete a bill, transaction, or account setting. Tally never sees or stores that agent's login credentials; our authentication provider (Auth0) manages the login and lets you revoke access at any time from its connected-apps settings.

One thing worth understanding plainly: once your data reaches an agent you've connected, how that agent - and whichever company operates it - stores, uses, or retains what it read is governed by that provider's own privacy policy, not this one, the same way anything you paste into any AI service's chat is governed by that service's policy rather than ours. Only connect an agent you trust with your financial information.

Who we share it with

We use a small number of service providers to run Tally, each of which processes data on our behalf under its own privacy policy:

  • Auth0 - authentication and login.
  • Amazon Web Services (AWS) - application hosting (Lambda, CloudFront, S3).
  • Neon - our PostgreSQL database provider, where your data is stored.
  • Stripe - payment processing for Tally Plus subscriptions, and, if you choose to connect a bank account, optional bank account syncing (Stripe Financial Connections). If you upgrade, your card details go directly to Stripe; Tally never sees, transmits, or stores your full card number, expiration date, or CVC. If you connect a bank account, Stripe handles the secure connection to your bank and shares only your transaction history and current balance with us, as described above.

We do not otherwise share your information with third parties, except where required by law.

Cookies and local storage

Tally and Auth0 use cookies and browser local storage only as needed to keep you signed in between visits. We don't use tracking or advertising cookies, and we don't use any third-party analytics service.

Blog analytics

On our blog we count page views so we know which articles are worth writing. Counting a page view stores nothing on your device and records no information about you: we keep the page address, the site that linked you to us (the site's name only, never the full address or anything you searched for), and the two-letter country our CDN reports. We never store your IP address.

We'll also ask, once, whether we may store a single randomly generated ID in your browser. It lets us tell repeat visits apart and see whether an article eventually led someone to sign up. It's entirely optional, it's off unless you accept, and if you decline we remember that and don't ask again. You can clear it any time by clearing site data in your browser.

If a link brought you here from one of our articles, the address you arrived on identifies that article, and we record which one alongside your account. That tells us which writing brings people in. It involves no cookie and no stored identifier.

We honour the "Do Not Track" and Global Privacy Control browser settings on the blog: with either enabled, we count nothing at all.

Your choices

  • You can export your bill data as a CSV at any time from an account's Bills page.
  • You can delete individual bills, transactions, or accounts from within the app.
  • To request a full export or deletion of your account and all associated data, contact us (below) and we'll handle it promptly.

Children's privacy

Tally is not directed at children under 13, and we do not knowingly collect information from them.

Changes to this policy

If we make material changes to this policy, we'll update the "Last updated" date above and, where appropriate, notify you in the app.

Contact us

Questions about this policy or your data? Email privacy@tallyahead.com.