← TallyTab

TallyTab — Privacy Policy

Status: draft for legal review — not yet in force. This draft is published for transparency while TallyTab is in development. Values shown in «guillemets» are still being confirmed and will be filled in before this policy takes effect.

Last updated: 29 July 2026

TallyTab exists to give you one calm, private place to see your money. That only works if you can trust us with the data behind it. This policy explains — in plain English — what we collect, why, where it lives, and the control you have over it.

Our promise is simple: no ads, and no selling your data. Ever.

Contents

  1. At a glance
  2. Who we are
  3. The data we collect
  4. What we deliberately do not collect
  5. Where your data comes from
  6. Why we use your data, and the lawful basis for each use
  7. Sensitive ("special category") data
  8. Open banking: how it works
  9. Who we share data with
  10. International transfers
  11. How long we keep your data
  12. How we protect your data
  13. Your rights
  14. Children
  15. Automated decision-making
  16. Cookies and our website
  17. Changes to this policy
  18. Contact us
  19. Governing law

1. At a glance


2. Who we are

TallyTab is made by Datavise Limited, a company registered in Scotland (company number SC817715), trading as TallyTab.

Registered office: 2nd Floor Clyde Offices, 48 West George Street, Glasgow, G2 1BP, United Kingdom.

Datavise Limited is the data controller for your personal data. "Data controller" is the legal term for the organisation that decides how and why your data is used — in other words, the one responsible for looking after it under UK data protection law (the UK GDPR and the Data Protection Act 2018).

We are registering with the Information Commissioner's Office (ICO), the UK's data protection regulator, and will show our registration reference here — «ICO registration number» — before this policy takes effect.

We are not required to appoint a Data Protection Officer; privacy@tallytab.co.uk reaches the people responsible for data protection.

For anything in this policy, contact us at privacy@tallytab.co.uk.


3. The data we collect

We collect the minimum we need to run the app. Here it is, grouped by where it comes from.

Account data

Launch waitlist

Financial data (via open banking)

When you choose to connect an account — a bank account, credit card, savings account or investment — we receive, read-only:

We only ever receive this after you have explicitly consented, and only through our FCA-authorised open banking provider (see section 8).

Things you add

Technical and diagnostic data

Support correspondence


4. What we deliberately do not collect

This list matters as much as the one above.


5. Where your data comes from

That's it. We don't obtain data about you from anywhere else.


6. Why we use your data, and the lawful basis for each use

You need an email address and a sign-in method to create an account — we can't provide the service without them. Everything else, including connecting any bank, is optional.

UK GDPR requires a lawful basis for every use of personal data. Here are ours. Where we rely on "legitimate interests", we name the interest — and you have the right to object (see section 13).

Purpose Data used Lawful basis
Sending the launch and beta updates you requested on our website Waitlist details Consent — you can withdraw it at any time
Creating and securing your account; signing you in; password resets Account data Contract — we can't provide the service without it
Connecting your banks and refreshing balances and transactions Financial data, connection metadata Consent — explicit, renewed every 90 days, withdrawable at any time
Showing your net worth, budgets, spending analytics and goals Financial data, things you add Contract
Running the rules and nudges you set up (for example, bill-jump alerts and budget tips) Financial data, things you add Contract
Managing your TallyTab Plus subscription Subscription status, transaction identifiers from Apple/Google Contract
Sending service emails (verification, password reset, security notices) Account data Contract, and legitimate interests for security notices (our interest: keeping your account safe)
Answering your support requests Support correspondence, account data Legitimate interests (our interest: running an effective, responsive support service)
Diagnosing problems and keeping the app reliable Server logs, scrubbed Sentry reports, store/device crash reports Legitimate interests (our interest: keeping the app stable and secure for everyone)
Detecting and preventing fraud, abuse and unauthorised access Account data, server logs (including IP addresses) Legitimate interests (our interest: protecting our users and our service)
Keeping accounting records and responding to lawful requests from authorities Subscription records, minimal account data Legal obligation

We never use your data for third-party advertising, and we never sell it. There is no lawful basis in the table for those things because we don't do them.


7. Sensitive ("special category") data

Your transactions can hint at sensitive things about you. A pharmacy payment, a therapy invoice, a union subscription, a donation to a religious or political organisation — the law calls information about health, beliefs, politics, trade union membership and similar "special category data", and it gets extra protection.

Here is how we treat that risk:

If you believe any of your data needs special handling, email privacy@tallytab.co.uk and we'll help.


8. Open banking: how it works

TallyTab connects to your accounts through «Yapily / TrueLayer / Finexer» (FRN «number»), a provider authorised by the Financial Conduct Authority (FCA) as an Account Information Service Provider (AISP). An AISP is a regulated company permitted to fetch read-only account information from your bank, with your permission, under the UK's open banking rules.

What this means in practice:

Our provider is a regulated business and a data controller in its own right for the account information service it provides — it handles your data under its own legal responsibilities and its own privacy notice: «link to provider's privacy notice». Its role is to act as the secure pipe between your bank and TallyTab.


9. Who we share data with

We share your data only with the service providers that run TallyTab — known as processors, companies that handle data strictly on our instructions. Each is bound by a contract to protect your data and use it only to provide their service to us.

Provider What they do for us Where
Supabase Sign-in (authentication) and our database London, UK (AWS eu-west-2)
Hetzner Hosts the server that runs our API (managed by us via Dokploy) EU
Sentry Receives privacy-filtered app/API fault diagnostics when configured «processing region and transfer safeguard to be confirmed before launch»
«Postmark or Resend — TBC» Sends service emails (verification, password reset, security notices) «US or EU — depends on final provider choice; Postmark stores data in the US»
Google (Google Workspace) Hosts our email, so support and privacy correspondence you send us is received and stored there «data region to be confirmed — may include the US»

A few organisations handle your data as independent controllers — meaning they decide how they use it under their own privacy policies, because your relationship with them is direct:

And to be explicit about who we do not share with: no advertisers, no ad networks, no data brokers, no "marketing partners". We do not sell your data to anyone.

We may disclose data if the law genuinely requires it — for example, a valid order from a UK court or authority. If that ever happens, we will disclose the minimum required and, where the law allows, tell you.

If Datavise Limited were ever acquired or merged, your data would remain protected by this policy, and we would notify you before any change took effect.


10. International transfers

Your account and financial data are stored in the UK and EU:

The UK Government has ruled that the EU provides adequate protection for personal data ("adequacy regulations"), so UK–EU storage requires no extra safeguards.

Email and diagnostics are the honest exceptions. Service emails may be sent by a provider with US infrastructure («Postmark or Resend — TBC»; Postmark stores data in the US), support correspondence lives in Google Workspace («data region to be confirmed»), and Sentry's final processing region and safeguards still need to be recorded. Where any provider processes your personal data in the United States — including remote support access to UK-hosted systems by a processor's US-based staff — we will only allow it with UK-approved safeguards in place: the UK Extension to the EU–US Data Privacy Framework, or the UK International Data Transfer Agreement (IDTA) / UK Addendum to the EU Standard Contractual Clauses. We will complete transfer risk assessments before launch and keep the table in section 9 up to date.


11. How long we keep your data

The short version: while your account is open, briefly afterwards for backups — plus the small set of records the law makes us keep.

Data How long we keep it
Launch waitlist details Until you withdraw consent, or 12 months after TallyTab launches, whichever comes first.
Account data, financial data, things you add While your account is open. Deleted when you delete your account.
Disconnected bank accounts The history stays in your TallyTab account so your record is complete. Deleted when you delete your account «or delete the connection's data in-app».
Dormant accounts If you stop using TallyTab, we warn you by email and then delete your account after «2–3 years» of inactivity.
Backups Deleted copies roll off our backups within «30» days.
Server logs (including IP addresses) «90 days», then deleted.
Crash reports «90 days», then deleted.
Support correspondence «12 months» after your query is resolved, then deleted.
Subscription and accounting records As long as UK tax and accounting law requires (typically six years).

How deletion actually works

We built deletion to be real, not a "soft delete" that hides your data while keeping it.


12. How we protect your data

No system is perfectly secure, and we won't pretend otherwise. If a breach ever put your rights at risk, we would notify you and the ICO without undue delay, as the law requires — and as we'd want done for us.


13. Your rights

UK GDPR gives you real rights over your data. Here is each one, and exactly how to use it with TallyTab.

How we respond. We will respond within one month. For unusually complex requests the law allows up to two further months — if we ever need that, we'll tell you within the first month and explain why. Exercising your rights is free.

Complaints. If you're unhappy with how we've handled your data, we'd genuinely like the chance to put it right first — email privacy@tallytab.co.uk. You also have the right to complain to the regulator at any time:

Information Commissioner's Office Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF ico.org.uk · 0303 123 1113


14. Children

TallyTab is for adults. You must be 18 or over to use it, and during our beta the service is available to UK residents only. We do not knowingly collect data from anyone under 18. If you believe someone under 18 has created an account, email privacy@tallytab.co.uk and we will delete it.


15. Automated decision-making

We make no automated decisions about you with legal or similarly significant effects. In plain terms: nothing TallyTab does automatically can affect your access to credit, your legal rights, or anything of similar weight.

Two features are automated, and both are purely informational:

We do not credit-score you, and we do not build behavioural profiles.


16. Cookies and our website

If that ever changes — for example, if we add privacy-respecting, first-party analytics — we will update this policy first and ask for consent where the law requires it.

The app sends push notifications — for nudges (generated by our service when your data refreshes) and occasional service messages. We deliver these through Firebase Cloud Messaging (a Google service) and, on iOS, through Apple's Push Notification service. Daily net-worth notifications are off until you turn them on. When enabled, their remote payload includes your current GBP net worth and its change since the previous daily update we sent. Those financial values pass through push infrastructure and may appear in system notification UI according to your device's preview settings. To route a notification to your device, we store a push notification token for that device on our servers, linked to your account. On sign-out, the app clears displayed and pending notifications, requests deletion of its local token, and durably queues removal of the matching server record before discarding the account/token pair needed for that cleanup. If the device is offline, the server removal is retained and retried on a later connected launch. Account deletion removes the server record as part of the account's database cascade. The notification content and token pass through Google's and/or Apple's push infrastructure to reach you. On Android the pseudonymous owner binding described in section 3 passes through Google's infrastructure as well. You can turn notifications off at any time in the app or in your device settings.


17. Changes to this policy

We'll update this policy when the service changes — for example, when our open banking provider is confirmed, or if we add a new processor.

Previous versions are available on request from privacy@tallytab.co.uk.


18. Contact us

By post: Datavise Limited (trading as TallyTab), 2nd Floor Clyde Offices, 48 West George Street, Glasgow, G2 1BP, United Kingdom.


19. Governing law

This policy, and any dispute arising from it, is governed by the law of England and Wales. Nothing in this section limits your statutory rights under UK data protection law, or your right to complain to the ICO, wherever you live in the UK.