TallyTab Privacy Policy
Status: draft for legal review, not yet in force. This draft is published for transparency while TallyTab is in development. Values shown in «guillemets» are still being confirmed and will be filled in before this policy takes effect.
Last updated: 16 August 2026
TallyTab exists to give you one calm, private place to see your money. That only works if you can trust us with the data behind it. This policy explains, in plain English, what we collect, why, where it lives, and the control you have over it.
Our promise is simple: no ads, and no selling your data. Ever.
Contents
- At a glance
- Who we are
- The data we collect
- What we deliberately do not collect
- Where your data comes from
- Why we use your data, and the lawful basis for each use
- Sensitive ("special category") data
- Open banking: how it works
- Who we share data with
- International transfers
- How long we keep your data
- How we protect your data
- Your rights
- Children
- Automated decision-making
- Cookies and our website
- Changes to this policy
- Contact us
- Governing law
1. At a glance
- We connect to your banks read-only, through an FCA-authorised open banking provider. We can see balances and transactions; we can never move your money.
- Your bank login details never touch TallyTab. You enter them with your bank, not with us.
- No ads. No selling your data. No advertising identifiers, no advertising SDKs and no data brokers. We do use a privacy-configured diagnostic service to find crashes and server faults, as described below.
- Pseudonymous usage analytics, which you can switch off. "Help improve TallyTab" sends usage events under a random, app-owned analytics identifier: which screens get used and where people get stuck. The identifier links events from the same app for an analytics lifetime, but is never joined to your TallyTab account, name or email. The events exclude balances, instrument identities, transaction contents and account details, and you can turn them off in one tap, in Settings › Preferences, at any time. See section 3.
- Your account and financial data are stored in the UK and EU. Our database runs in London. Support and service emails may be handled by providers with US infrastructure, under UK-approved safeguards (see section 10).
- Deleting your account (in the app, or by emailing us) erases everything in our database in one operation: your login, your accounts, your transactions, your budgets. The only things that outlive it are backup copies (gone within 7 days), support emails, and the small set of records the law requires us to keep (see section 11).
- Take your data with you. On any plan, ask us for a full, machine-readable copy of your data, free of charge. TallyTab Plus also includes CSV export of your transactions directly in the app.
- Questions or requests: privacy@tallytab.co.uk. We respond within one month.
2. Who we are
TallyTab is made by Datavise Limited, a company registered in Scotland (company number SC817715), trading as TallyTab.
Registered office: 2nd Floor Clyde Offices, 48 West George Street, Glasgow, G2 1BP, United Kingdom.
Datavise Limited is the data controller for your personal data. "Data controller" is the legal term for the organisation that decides how and why your data is used, in other words the one responsible for looking after it under UK data protection law (the UK GDPR and the Data Protection Act 2018).
We are registering with the Information Commissioner's Office (ICO), the UK's data protection regulator, and will show our registration reference here, «ICO registration number», before this policy takes effect.
We are not required to appoint a Data Protection Officer; privacy@tallytab.co.uk reaches the people responsible for data protection.
For anything in this policy, contact us at privacy@tallytab.co.uk.
3. The data we collect
We collect the minimum we need to run the app. Here it is, grouped by where it comes from.
Account data
- Your email address, and either a password (stored only as a cryptographic hash; we never keep the password itself) or your Google or Apple sign-in identity if you choose to sign in that way.
- Your subscription status: whether you're on the free tier or TallyTab Plus, plus the transaction identifiers Apple or Google send us to confirm it. Apple and Google hold the payment records; we never see your card details.
Launch waitlist
- If you join the website waitlist, we collect your email address, plus your first name and whether you use iPhone or Android if you choose to provide them. We use these details only for TallyTab launch and beta updates. Every one of those emails carries an unsubscribe link, and you can also withdraw at any time by emailing privacy@tallytab.co.uk.
Financial data (via open banking)
When you choose to connect an account (a bank account, credit card, savings account or investment), we receive, read-only:
- Balances for each connected account.
- Transactions: dates, amounts, merchant or payee names, and reference text.
- Connection metadata: which institution the account is with, the account type, and the status of the connection (for example, when consent is due for renewal).
We only ever receive this after you have explicitly consented, and only through our FCA-authorised open banking provider (see section 8).
Things you add
- Your name, and any display names you give your accounts.
- Accounts you enter yourself: the name, type, balance and currency of any account you add manually rather than through open banking.
- Investments you track, for each holding: the instrument, the quantity, what you paid for it (average cost, in the instrument's own currency), the dates you acquired or disposed of it, and any sale price. We use these to work out your gain or loss. We never place trades, never take custody of any asset, and never hold cash or cryptocurrency on your behalf.
- Categories, notes, budgets, goals, regular payments and rules you create in the app.
- Any changes you make to how transactions are categorised.
- History we derive from the above: monthly net-worth points and a record of each account's balance over time, so your charts have a past.
Technical and diagnostic data
- Server logs. When the app talks to our servers, our application log records the endpoint called, the time, the response status, how long the request took and a request ID. It does not record your IP address. Your IP is held briefly in memory to apply rate limits, and is never written to a log. Our hosting and database providers keep their own infrastructure access logs, which do contain IP addresses; those are retained for «period to be confirmed».
- Crash and error diagnostics. TallyTab can send technical fault reports to Sentry when a release is configured with our Sentry project. Reports may include the app/operating-system version, device model, failed operation and a stack trace. We disable request bodies, default personal-data collection and stack-frame local variables, and scrub identifiers, email addresses, secrets and money values before a report leaves our systems. Apple or Google may also provide device-level diagnostics if your device sharing settings allow it.
- Push notification token. So we can deliver notifications, we store a token that identifies your device to Firebase Cloud Messaging and, on iOS, Apple's Push Notification service. It is linked to your account. When you sign out, the app requests deletion of its local token and durably queues removal of the matching account/token record from our server; if the device is offline, that server removal is retried when connectivity returns. Deleting your account also deletes the server record (see section 16).
- Android notification owner binding. Android notification payloads include a stable, one-way SHA-256 value derived from your account ID. The app compares it with the current signed-in account before showing a notification, so a delayed message cannot appear for the next person using the device. Google receives this pseudonymous value with the payload, but not the raw account ID.
Usage analytics: not account-linked, and you can switch them off
"Help improve TallyTab" counts how the app is used so we can make it better. It is on by default. We tell you about it here, in this policy, and the switch lives in Settings › Preferences for as long as you have the app: one tap, no account needed, no need to email anyone. Switch it off and collection stops.
The proposed default-on design would rely on the statistical purposes exception in PECR Schedule A1 paragraph 5, alongside legitimate interests under UK GDPR. That proposal is pending counsel validation and is not approved for release. Counsel must confirm whether this 41-event, 90-day raw-event design qualifies or whether it needs opt-in consent or a shorter aggregate-and-delete model. The technical boundary is designed to keep the events about how the app is used, not the account holder's identity:
- What we receive. A fixed list of 41 event names describing what happened, not what it was worth: for example "onboarding viewed", "bank-connect step viewed", "asset-add started", "asset search completed", "paywall viewed" and "purchase completed". Events can carry short labels from a fixed vocabulary: the screen or step, account/stock/crypto, buy/sell, a result-count range, a coarse failure reason, and where a flow was opened from. This means the stream can reveal that an app instance viewed a stock/crypto portfolio or holding or started, completed, failed or cancelled a coarse buy/sell flow. PostHog also receives the app version/build, operating-system family, analytics-SDK version, event time, a random event UUID and random analytics/session identifiers. The app rejects any missing, extra or unrecognised event property before it is sent, then filters the completed SDK payload a second time.
- What we never receive. Your balances, net worth, transactions, merchants,
account names or numbers, budgets, goals, email address or name. Asset events
never contain your search text, an instrument name or symbol, instrument or
account identifiers, quantities, prices or provider responses. We also strip
device model/name, OS version, carrier, locale, timezone, screen dimensions,
network state and any device/browser user-agent event property. The HTTPS
request still contains the PostHog SDK's own library/version
User-Agentheader. This boundary is enforced in the app's code by an exact per-event schema and automated tests, not merely by policy. - It is not linked to your account. Events carry a random, app-owned analytics identifier, never your account ID, your email address or your name. It lets PostHog group a pseudonymous app-instance journey during the 90-day event-retention window, but we do not use individual journey/person views and cannot identify the TallyTab account from that identifier. It is excluded from device backups and replaced on sign-out or a direct account change, so a shared phone does not combine two account sessions into one analytics journey.
- Who processes it. PostHog, on their EU Cloud (Frankfurt, Germany), as our processor under a data processing agreement, and only to help us improve TallyTab. PostHog's infrastructure necessarily receives the source IP needed to deliver the HTTPS request. The app sets PostHog's GeoIP-disable field on every event, so PostHog does not add that IP or a derived location to the analytics event. PostHog's handling of infrastructure data is governed by our data processing agreement.
- No recording, profiles or automatic capture. We do not record or replay your screen, create a PostHog person profile, automatically capture controls, deep links, push notifications or errors, or use analytics feature flags. Those features are explicitly disabled in the app's configuration.
- Nothing else uses it. We do not use these events for advertising, for measuring marketing, or to build any profile of you.
Support correspondence
- If you email us (support@, privacy@ or hello@tallytab.co.uk), we keep the correspondence so we can help you and refer back to it if you contact us again.
- If you use the contact form at tallytab.co.uk/contact, we store the name, email address and message you send so we can answer you. It is forwarded to the same inbox as an email would be, and kept for the same period as any other support correspondence (see section 11). You do not need an account to use it, and we do not link what you send to one.
4. What we deliberately do not collect
This list matters as much as the one above.
- No advertising identifiers. We never read your device's ad ID.
- No advertising SDKs. Sentry (diagnostics) and PostHog (usage analytics) are the only third-party SDKs in the app that send us anything, and neither is used to profile you, measure marketing or build advertising audiences. Sentry is restricted as described in section 3. Switching analytics off immediately blocks new app events and attempts to purge the pinned SDK's known local queues. If deletion cannot be confirmed, collection stays disabled and a later start retries cleanup before any old queue can be used. An HTTPS request that had already begun cannot be recalled and may finish as processing started before the objection.
- No financial values or transaction contents in analytics. The fixed event list can include coarse account/stock/crypto, portfolio/holding and buy/sell UI actions. It cannot include a balance, net worth, instrument/search/symbol, quantity, price, transaction contents, merchant, account details or email address. The exact allowlist that enforces this is covered by automated tests.
- No account identity in analytics. Usage events are never tagged with your account, email address or name. The random identifier links an app-instance journey, but TallyTab does not join it back to an account or use individual journey views.
- No session recording or screen capture. We never record your screen, replay your session or capture screenshots of the app.
- No data brokers. We don't buy data about you, and we don't supply data to brokers.
- No selling your data. We don't sell, rent or trade your personal data to anyone, for any purpose.
- No bank credentials. Your online banking username and password are entered with your bank, never with us. They never pass through our systems.
- No payment card details. TallyTab Plus (£2.99/month after any store-confirmed 7-day introductory trial) is billed through the App Store or Google Play. Apple and Google handle all payment data; we only receive confirmation of your subscription status and entitlement period.
- No biometric data. If you enable the optional app lock, Face ID or your fingerprint is checked by your phone's operating system. We only receive a yes/no answer. Your biometric data never leaves your device and we never see it.
5. Where your data comes from
- From you: when you join the launch waitlist, create an account, add categories, budgets, goals, rules and notes, or email us.
- From your banks and other financial institutions: via our open banking provider, only after you connect an account and give explicit consent.
- From Apple and Google: your sign-in identity (if you use Sign in with Apple or Google), confirmation of your subscription status, and crash reports if your device settings share them.
- From the app and API when a fault occurs: the scrubbed technical diagnostic data described in section 3, sent to Sentry only when that service is configured.
- From your device: the server logs described in section 3, generated when the app talks to our servers.
That's it. We don't obtain data about you from anywhere else.
6. Why we use your data, and the lawful basis for each use
You need an email address and a sign-in method to create an account. We can't provide the service without them. Everything else, including connecting any bank, is optional.
UK GDPR requires a lawful basis for every use of personal data. Here are the bases used or proposed in this draft. Where we rely on "legitimate interests", we name the interest, and you have the right to object (see section 13).
| Purpose | Data used | Lawful basis |
|---|---|---|
| Sending the launch and beta updates you requested on our website | Waitlist details | Consent: you can withdraw it at any time |
| Creating and securing your account; signing you in; password resets | Account data | Contract: we can't provide the service without it |
| Connecting your banks and refreshing balances and transactions | Financial data, connection metadata | Consent: explicit, renewed every 90 days, withdrawable at any time |
| Showing your net worth, budgets, spending analytics and goals | Financial data, things you add | Contract |
| Providing the daily net-worth update and running rules and nudges you configure (for example, bill-jump alerts and budget tips) | Financial data, things you add, push token | Contract |
| Managing your TallyTab Plus subscription | Subscription status, transaction identifiers from Apple/Google | Contract |
| Sending service emails (verification, password reset, security notices) | Account data | Contract, and legitimate interests for security notices (our interest: keeping your account safe) |
| Answering your support requests | Support correspondence, account data | Legitimate interests (our interest: running an effective, responsive support service) |
| Diagnosing problems and keeping the app reliable | Server logs, scrubbed Sentry reports, store/device crash reports | Legitimate interests (our interest: keeping the app stable and secure for everyone) |
| Understanding how the app is used so we can improve it | Pseudonymous, app-linked usage-analytics events (no account ID) | Proposed legitimate interests, pending counsel validation (our proposed interest: knowing which parts of the app work so we can fix the parts that don't). This must not ship under the default-on model until the reopened LIA and PECR analysis are approved. You can object in one tap in Settings › Preferences |
| Detecting and preventing fraud, abuse and unauthorised access | Account data, server logs (including IP addresses) | Legitimate interests (our interest: protecting our users and our service) |
| Keeping accounting records and responding to lawful requests from authorities | Subscription records, minimal account data | Legal obligation |
We never use your data for third-party advertising, and we never sell it. There is no lawful basis in the table for those things because we don't do them.
7. Sensitive ("special category") data
Your transactions can hint at sensitive things about you. A pharmacy payment, a therapy invoice, a union subscription, a donation to a religious or political organisation: the law calls information about health, beliefs, politics, trade union membership and similar "special category data", and it gets extra protection.
Here is how we treat that risk:
- We don't profile you. We never analyse your transactions to work out your health, religion, politics, sexuality or anything else about you as a person.
- We don't infer. Transaction categorisation is a convenience feature. It sorts spending into everyday buckets like "Groceries" or "Transport" based on merchant information. It draws no conclusions about you.
- You control the categories. You can rename, recategorise or create categories however you like, and your choices always win.
- Nothing is shared. Your transactions are used to show you your money, nothing more.
If you believe any of your data needs special handling, email privacy@tallytab.co.uk and we'll help.
8. Open banking: how it works
TallyTab connects to your accounts through Yapily Connect Ltd, a company registered in England and Wales (number 11598433), registered office 86–90 Paul Street, London, EC2A 4NE, authorised and regulated by the Financial Conduct Authority under Financial Services Register number 827001 as an Account Information Service Provider (AISP). An AISP is a regulated company permitted to fetch read-only account information from your bank, with your permission, under the UK's open banking rules.
Yapily Connect also holds payment initiation permissions on the FCA register. TallyTab uses only its account information service. We have never integrated any capability to move money, and there is none in the app.
What this means in practice:
- You consent first. Nothing is connected until you choose an institution in the app and approve the connection with your bank, usually via your banking app.
- Your credentials stay with your bank. You authenticate directly with your bank. Your online banking username and password are never entered into TallyTab and never pass through our systems, or our provider's.
- Read-only, always. We receive balances, transactions and account details. Neither TallyTab nor the provider can move money, make payments or change anything on your accounts.
- Consent expires every 90 days. Under open banking rules, your consent lapses after 90 days unless you renew it. The app will prompt you; if you do nothing, the connection simply stops refreshing.
- You can revoke at any time. Disconnect an account in the app, or withdraw access directly with your bank. Either works, immediately: we stop receiving new data from that account. The history already in TallyTab stays, so your net worth record remains complete, and you can remove it by deleting the account in the app, or by deleting your TallyTab account.
Yapily Connect's role is to act as the secure pipe between your bank and TallyTab. It handles your data under its own privacy notice, at yapily.com/legal/privacy-policy, and its terms for end users are at yapily.com/legal/end-user-terms.
«Whether Yapily Connect acts as our processor or as an independent controller for this service is being confirmed against our signed agreement; section 9 names its role once settled.»
9. Who we share data with
We share your data only with the service providers that run TallyTab, known as processors, companies that handle data strictly on our instructions. Each is bound by a contract to protect your data and use it only to provide their service to us.
| Provider | What they do for us | Where |
|---|---|---|
| Supabase | Sign-in (authentication) and our database | London, UK (AWS eu-west-2) |
| Hetzner | Hosts the server that runs our API (managed by us via Dokploy) | Finland |
| Sentry | Receives privacy-filtered app and API fault diagnostics | European Union |
| PostHog | Receives pseudonymous, non-account-linked usage-analytics events from the app (unless you switch analytics off) and anonymous, cookieless page statistics from our website | European Union (Frankfurt, Germany) |
| Resend | Sends service emails (verification, password reset, security notices) and forwards contact-form messages to our own inbox | European Union (Ireland) |
| Google (Google Workspace) | Hosts our email, so support and privacy correspondence you send us is received and stored there | Global, including the United States (see section 10) |
Market data, and why it never involves you
We show prices for shares, funds and cryptocurrencies using Marketstack, CoinGecko, the European Central Bank (exchange rates) and Yahoo Finance (to confirm which currency an instrument is quoted in), and company logos for shares and funds come from Elbstream. These are not processors of your personal data, because we never send them any:
- Prices are fetched for our whole instrument catalogue on a schedule, not per person and not on demand. No price provider can tell what you hold, or that you exist.
- Searching is the one exception, and it still isn't personal. If you search for an instrument we don't already have catalogued, your search term is sent to Marketstack or CoinGecko by our server, not by your device, so they receive a search term from us with no name, account, device or IP of yours attached, and no way to link it to you.
- Logos and icons are copied onto our own storage and served from there, specifically so your device never fetches anything directly from a market-data vendor. They never see your IP address.
A few organisations handle your data as independent controllers, meaning they decide how they use it under their own privacy policies, because your relationship with them is direct:
Yapily Connect Ltd (FCA-authorised AISP, FRN 827001), which provides its regulated account information service under its own authorisation and its own privacy notice. Section 8 explains its role. Yapily's own sub-processors include Google LLC and Amazon Web Services EMEA SARL, under its transfer safeguards.
Apple and Google, for Sign in with Apple/Google, App Store / Google Play billing, device-level crash reporting, and push notification delivery: Google (Firebase Cloud Messaging) and, on iOS, Apple (Push Notification service) carry our notifications and the device token to your device (see sections 3 and 16).
Your bank or financial institution, which decides how to handle your accounts and your open banking consent at its end.
And to be explicit about who we do not share with: no advertisers, no ad networks, no data brokers, no "marketing partners". We do not sell your data to anyone.
We may disclose data if the law genuinely requires it: for example, a valid order from a UK court or authority. If that ever happens, we will disclose the minimum required and, where the law allows, tell you.
If Datavise Limited were ever acquired or merged, your data would remain protected by this policy, and we would notify you before any change took effect.
10. International transfers
Everything that holds your account or financial data sits in the UK or the EU:
- Database and authentication: London, UK (Supabase, AWS eu-west-2).
- API server: Finland (Hetzner).
- Service emails: Ireland (Resend).
- Fault diagnostics: European Union (Sentry).
- Usage analytics, unless you switch them off: Germany (PostHog EU Cloud).
- Open banking: UK (Yapily Connect Ltd).
The UK Government has ruled that the EU provides adequate protection for personal data ("adequacy regulations"), so UK and EU storage requires no additional safeguards.
There is one exception, and it is email you send us. Our mailboxes run on Google Workspace on a plan without regional data controls, so support and privacy correspondence may be processed outside the UK and EU, including in the United States. Google makes those transfers under the UK Addendum to the EU Standard Contractual Clauses and its certification under the UK Extension to the EU–US Data Privacy Framework. This affects only what you choose to put in an email to us. It never affects your account, balances, transactions or holdings, which stay in the UK and EU as listed above.
Where a provider's staff outside the UK or EU can reach UK-hosted systems for support purposes, the same safeguards apply. This includes PostHog: your analytics events are stored in Germany, but PostHog Inc is a US company, and our data processing agreement with it incorporates the UK Addendum to the EU Standard Contractual Clauses to cover any access from the United States. «Supabase's transfer mechanism for that access is being confirmed against its DPA.»
11. How long we keep your data
The short version: while your account is open, briefly afterwards for backups, plus the small set of records the law makes us keep.
| Data | How long we keep it |
|---|---|
| Launch waitlist details | Until you withdraw consent, or 12 months after TallyTab launches, whichever comes first. |
| Account data, financial data, things you add | While your account is open. Deleted when you delete your account. |
| Disconnected bank accounts | The history stays in your TallyTab account so your record is complete. Deleted when you remove the account in the app, or when you delete your TallyTab account. |
| Backups | Deleted copies roll off our database backups within 7 days. |
| Application server logs | Retained «period to be confirmed». These contain no IP address (see section 3). Our hosting and database providers keep separate infrastructure access logs that do, on their own schedules. |
| Crash reports | «90 days», then deleted. |
| Pseudonymous usage-analytics events | Proposed: 90 days, then deleted, subject to counsel approving that raw-event window or requiring a shorter aggregate-and-delete model. Switching analytics off immediately blocks new app events and attempts to purge known local queues; if deletion cannot be confirmed, collection stays disabled and later startup retries sanitation. An HTTPS request already in flight cannot be recalled. Because the analytics identifier is not joined to your account, an account-erasure request cannot select its server-side events. TallyTab uses the stream only for aggregate product statistics, never to make a decision about an individual. |
| Support correspondence | 12 months after your query is resolved, then deleted. |
| Subscription and accounting records | As long as UK tax and accounting law requires (typically six years). |
How deletion actually works
We built deletion to be real, not a "soft delete" that hides your data while keeping it.
- Go to Settings → Delete account in the app, or email privacy@tallytab.co.uk.
- Deleting your account deletes your login identity itself. Every table in our database is linked to that identity with an automatic cascade, so your accounts, transactions, budgets, goals, rules, notes and settings are all erased in a single database operation.
- There are no partial deletes: if anything were to fail, the whole operation fails visibly and we fix it. You're never left half-deleted without knowing.
- Copies in backups expire within 7 days as our database backups roll off.
- Two things live outside that database cascade and are deleted separately, on the schedules in the table above: support emails (stored in Google Workspace) and the minimal subscription and accounting records the law requires us to keep.
12. How we protect your data
- Encryption in transit. All traffic between the app, our servers and our providers uses TLS. Release builds of the Android app refuse plaintext HTTP connections outright.
- Row-level security. Our database enforces rules at the level of each individual record, so your data can only ever be read by your own authenticated account, a safeguard built into the database itself, not just the app.
- No bank credentials. The most sensitive secret, your bank login, never touches our systems at all (see section 8).
- Hashed passwords. If you use a password, we store only a cryptographic hash, never the password itself.
- Protected on your device. Your session tokens are stored encrypted with a hardware-backed key wherever the device supports it: Android Keystore (AES-GCM) on Android, the Keychain on iOS.
- Optional app lock. You can require Face ID, your fingerprint, or your device's PIN, pattern or passcode to open the app. The check is performed entirely by your phone's operating system. We receive only a yes or no. Your biometric data and your device passcode never leave your device, and we never see them.
- Kept out of cloud backups. On Android, your session, app-lock state, cached financial data, push token and pending verification are excluded from Google Drive backup and from device-to-device transfer. Only cosmetic preferences, your theme and home-screen layout, are ever copied. Neither app keeps a local database, so there is no store of your transactions or holdings sitting on the handset.
- Minimal collection. The strongest protection is not holding data in the first place, which is why the list in section 4 is so long.
No system is perfectly secure, and we won't pretend otherwise. If a breach ever put your rights at risk, we would notify you and the ICO without undue delay, as the law requires, and as we'd want done for us.
13. Your rights
UK GDPR gives you real rights over your data. Here is each one, and exactly how to use it with TallyTab.
- Access. Ask for a copy of the personal data we hold about you and how we use it. Email privacy@tallytab.co.uk.
- Rectification. Correct anything inaccurate. You can edit your details, categories and everything you've added directly in the app; for anything else, email us.
- Erasure. Delete your data with Settings → Delete account in the app, or email privacy@tallytab.co.uk. Section 11 explains exactly what happens: everything in our database is erased in one operation, and the few records the law requires us to keep are listed there.
- Portability. Take your data with you. On any plan, email privacy@tallytab.co.uk for a full copy of your data in a machine-readable format, free of charge. TallyTab Plus also includes CSV export of your transactions directly in the app.
- Restriction. Ask us to pause processing of your data while a question or dispute is resolved. Email privacy@tallytab.co.uk.
- Objection. Object to any processing we base on legitimate interests (see the table in section 6). Email privacy@tallytab.co.uk; we'll stop unless we can show compelling grounds. For usage analytics you don't need to email anyone: switch "Help improve TallyTab" off in Settings › Preferences at any time. The app immediately blocks new events and attempts to purge its known unsent queues. If deletion cannot be confirmed, collection stays disabled and sanitation is retried before any later start; a request that was already in flight cannot be recalled.
- Withdraw consent. For open banking connections, disconnect the account in the app, or revoke access with your bank. Either way, we stop receiving new data immediately. The history already in your TallyTab account stays so your record is complete, and is deleted when you remove the account in the app or delete your TallyTab account (see section 11). Withdrawing consent doesn't affect the lawfulness of what happened before.
- Rights around automated decisions. We make no automated decisions with legal or similarly significant effects (see section 15), but if you're ever unsure, ask.
How we respond. We will respond within one month. For unusually complex requests the law allows up to two further months. If we ever need that, we'll tell you within the first month and explain why. Exercising your rights is free.
Complaints. If you're unhappy with how we've handled your data, we'd genuinely like the chance to put it right first. Email privacy@tallytab.co.uk. You also have the right to complain to the regulator at any time:
Information Commissioner's Office Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF ico.org.uk · 0303 123 1113
14. Children
TallyTab is for adults. You must be 18 or over to use it, and during our beta the service is available to UK residents only. We do not knowingly collect data from anyone under 18. If you believe someone under 18 has created an account, email privacy@tallytab.co.uk and we will delete it.
15. Automated decision-making
We make no automated decisions about you with legal or similarly significant effects. In plain terms: nothing TallyTab does automatically can affect your access to credit, your legal rights, or anything of similar weight.
Two features are automated, and both are purely informational:
- Transaction categorisation sorts spending into categories based on merchant information. It's a display convenience. You can override any category, and your choice sticks.
- Nudges (bill-jump alerts, budget tips, payment-due reminders) are informational suggestions generated by our service when your data refreshes, and shown as notifications by the app on your device. You can ignore or disable them at any time.
We do not credit-score you, and we do not build behavioural profiles.
16. Cookies and our website
- Our website (tallytab.co.uk) sets no cookies and stores nothing on your device. It runs cookieless, anonymous analytics (PostHog, hosted in the EU) so we can see which pages are read and which channel a visit came from: no identifier is saved to your browser, nothing links a visit to you or to an account, we disable IP-based location lookup, and we honour your browser's Do Not Track setting. If you join the waitlist, the signup records the channel that brought you (for example "reddit"), nothing more.
- The app contains no advertising SDKs and sets no advertising identifiers. Its optional Sentry integration is limited to technical diagnostics as described in section 3. Its usage analytics (PostHog) store a random analytics identifier on your device. The proposed default-on model would rely on the statistical purposes exception in PECR Schedule A1 paragraph 5, but that legal conclusion is pending counsel validation for the 41-event/90-day design. Events are never joined to your account and exclude financial values, instruments, searches/symbols, account details and transaction contents, but can disclose coarse stock/crypto portfolio and buy/sell UI activity. You can switch them off in one tap, in Settings › Preferences, at any time.
If that ever changes (for example, if we start collecting something not listed in section 3), we will update this policy first and ask for consent where the law requires it.
The app sends push notifications: for nudges (generated by our service when your data refreshes) and occasional service messages. We deliver these through Firebase Cloud Messaging (a Google service) and, on iOS, through Apple's Push Notification service. Daily net-worth notifications are enabled by default for new accounts and can be switched off at any time in TallyTab Settings. Their remote payload includes your current GBP net worth and its change since the previous daily update we sent. Those financial values pass through push infrastructure and may appear in system notification UI according to your device's preview settings. To route a notification to your device, we store a push notification token for that device on our servers, linked to your account. On sign-out, the app clears displayed and pending notifications, requests deletion of its local token, and durably queues removal of the matching server record before discarding the account/token pair needed for that cleanup. If the device is offline, the server removal is retained and retried on a later connected launch. Account deletion removes the server record as part of the account's database cascade. The notification content and token pass through Google's and/or Apple's push infrastructure to reach you. On Android the pseudonymous owner binding described in section 3 passes through Google's infrastructure as well. You can turn notifications off at any time in the app or in your device settings.
17. Changes to this policy
We'll update this policy when the service changes: for example, when our open banking provider is confirmed, or if we add a new processor.
- For material changes, anything that meaningfully affects your data or your rights, we will notify you in the app before the change takes effect, with time to read it and, if you wish, export your data and leave.
- For minor changes (clarifications, typo fixes), we'll simply update the date at the top.
Previous versions are available on request from privacy@tallytab.co.uk.
18. Contact us
- Privacy and data rights: privacy@tallytab.co.uk
- Help using the app: support@tallytab.co.uk
- Anything else: hello@tallytab.co.uk
By post: Datavise Limited (trading as TallyTab), 2nd Floor Clyde Offices, 48 West George Street, Glasgow, G2 1BP, United Kingdom.
19. Governing law
This policy, and any dispute arising from it, is governed by Scots law. Nothing in this section limits your statutory rights under UK data protection law, or your right to complain to the ICO, wherever you live in the UK.