Privacy Policy
Last updated: September 11, 2026
This policy explains what personal data Tally (“Tally”, “we”, “us”) collects, why, who we share it with, and the rights you have over it. It applies to the Tally web app, the iOS and macOS apps, and the client portal.
Who is responsible for your data
Tally is operated by Nicholas Marks, a sole proprietor doing business as Tally, based in San Francisco, California, USA. For privacy questions, or to exercise any of the rights described below, contact support@tally-works.com.
For people in the European Union, Nicholas Marks (doing business as Tally) is the data controller for the account and usage data described in “Information we collect.” Where a design studio uses Tally to manage information about its own clients, the studio is the controller of that information and Tally acts as its processor — see “If you are a studio: data about your clients” below.
Information we collect
- Account information — your name, email address, and a hashed password. Passwords are hashed with bcrypt and never stored in plain text. Optionally a profile photo, job title, and phone number.
- Content you create — projects, time entries, invoices, vendors, messages, and the client and contact records you enter (which can include your clients’ names, email addresses, phone numbers, and postal addresses).
- Payment information — subscription and invoice payments are processed by Stripe. Card and bank details are handled directly by Stripe and are never stored on Tally’s servers. We retain non-sensitive records of payments (amount, date, status).
- Optional bank-feed information — if a studio owner chooses to connect an account through Plaid, Tally receives account identifiers and metadata, balances, and up to 24 months of transaction history, including dates, amounts, descriptions, merchant information, and categories. Tally never receives or stores online-banking usernames or passwords.
- Usage and device data — pages viewed, actions taken, approximate location (country/region/city) derived from your IP address, your IP address, and browser and device information. This is used for product analytics and abuse prevention.
- Communications — emails, support requests, and in-app messages you send us or other users.
Optional Gmail connection
If you choose to connect Gmail, Tally receives your Google account identifier and email address, and accesses email headers, message text, and attachments to let you review project conversations. Google grants read access to the connected mailbox. Your automatic matching setting and specific project, contact, or conversation choices determine which conversations appear for review; they do not narrow the permission granted by Google. To identify matches during synchronization, Tally temporarily processes message headers, including sender, recipients, subject, and date, from changed conversations across the mailbox, including conversations outside your choices. If you enable automatic project matching, Tally also temporarily reads recent message text to identify project and order references and match known contacts. Unrelated message content is not retained. Review includes incoming and sent messages from the past 30 days and excludes unsent drafts, spam, and trash.
Email in Tally is private to the studio owner who connects the account. Selecting a project does not share email with other studio users or clients. The current integration does not send replies, change your mailbox, update orders, or send your email to an AI model provider. We do not use Google user data for advertising or to develop or train generalized AI models. Tally’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements.
We encrypt the stored connection credentials, account identity, and conversation choices. We also retain conversation identifiers, synchronization progress, and minimal connection and security records needed to operate the feature. Automatic matching additionally stores an encrypted subject, sender, and matching evidence for each indexed conversation, for no more than 30 days after its latest included message. Stopping automatic matching removes this index. Message text and attachments are processed temporarily in memory; Tally does not keep an archive of their contents. Our hosting, database, and backup providers listed below process the relevant data to operate this service. Files you choose to download are saved on your device.
How we use it and our legal bases
For people in the EU/UK, we rely on the following legal bases (GDPR Article 6):
- To provide the service (create your account, store your data, send transactional emails, process payments) — performance of our contract with you.
- To secure and improve the product (analytics, abuse prevention, debugging) — our legitimate interests, balanced against your rights.
- Non-essential cookies and analytics — your consent, where required.
- To meet legal and tax obligations (retaining invoice and payment records) — compliance with a legal obligation.
If you are a studio: data about your clients
When a design studio enters information about its clients, projects, and vendors, the studio is the data controller and Tally is the data processor. We process that data only to provide the service and on the studio’s instructions. Studios that need a Data Processing Agreement (GDPR Article 28) can request one at support@tally-works.com.
Service providers we share data with
We use a small set of vetted providers (sub-processors) to run Tally:
- Stripe — payment processing (subscriptions and client invoices).
- Plaid — optional bank-account connection and transaction-feed services initiated by a studio owner.
- Resend — transactional and notification email delivery.
- Google — address autocomplete through Places API and optional Gmail account connection and email retrieval.
- Apple (APNs) — push notifications to the iOS and macOS apps.
- Render — application hosting and scheduled tasks.
- PlanetScale — managed PostgreSQL database hosting.
- Cloudflare — public DNS, edge security and proxying, plus R2 uploaded-file and encrypted-backup storage.
- GitHub — storing screenshots you attach to in-app feedback.
We do not sell or rent your personal data, and we do not share it for third-party advertising.
International data transfers
Tally is based in the United States and uses service providers that process data in the United States and through global infrastructure. If you are in the EU, UK, or another region with data-transfer rules, your data may be transferred to and processed in the United States and other countries outside your home region. Where required, we rely on appropriate safeguards for these transfers — primarily the EU Standard Contractual Clauses, together with the EU–US Data Privacy Framework where a provider is certified.
Cookies and similar technologies
- Strictly necessary — the
sb_session/sb_client_portal_sessioncookies keep you logged in. These are required for the service to work and are not used for tracking. - Analytics — a
tally_sidcookie and similar first-party identifiers help us understand how the product is used. They are not used for third-party advertising, and you can block or clear them through your browser settings.
How long we keep data
We keep account and content data while your account is active and for 90 days after you delete your account, to allow recovery, after which it is permanently deleted. Invoice and payment records are kept for up to 10 years to meet tax and accounting obligations. Analytics data is retained for up to 26 months. Encrypted disaster-recovery backups can retain deleted data for up to 35 additional days before automatic expiration. Backup access is restricted to recovery and documented restore testing.
If you connect a bank feed, encrypted raw provider receipts become eligible for automated deletion after 30 days and normalized transaction history after seven calendar years. The deletion job runs when Tally starts and every 15 minutes, so deletion normally occurs on the next successful run; a delayed or failed run can extend that timing until recovery. Disconnecting a feed revokes Tally’s provider access and removes the stored access token. After all feeds are disconnected, a studio owner can delete imported bank-feed data from Tally; minimal deletion and consent records may be retained to demonstrate that the request was completed. Source accounting records created separately in Tally are not deleted as part of a bank-feed deletion.
For Gmail, saved conversation choices and connection credentials remain until you remove them or disconnect. Cached conversation references expire 30 days after the latest eligible message and are removed on a successful background cleanup; a new eligible message can extend that period. Explicit conversation choices remain until you change them or disconnect. Disconnecting in Settings stops new reads and removes the account identity, reading credentials, choices, and conversation references from active storage. A request already in progress may still finish, but it cannot restore the disconnected connection’s data.
Google grant removal is separate from deletion in Tally. We temporarily retain an encrypted credential solely to retry removal during a 24-hour window, and delete it after confirmed removal or the next successful cleanup after that window. If removal cannot be confirmed, Settings directs you to remove Tally in your Google account’s third-party connections. Minimal connection, consent, and security records may remain. These Gmail deletion rules take precedence over the general 90-day recovery period; encrypted backups can retain deleted records for up to 35 additional days.
Your rights
Depending on where you live, you may have the right to access, correct, delete, export, or restrict the processing of your personal data, to object to certain processing, and to withdraw consent at any time. To exercise any of these, email support@tally-works.com.
If you are in the EU/UK and believe we have not handled your data properly, you have the right to lodge a complaint with your local data protection authority. We do not currently maintain an EU representative under GDPR Article 27.
Security
We use industry-standard measures to protect your data, including encryption in transit, hashed passwords, per-tenant database isolation, and access controls. No system is perfectly secure; we will notify affected users and authorities of a breach where required by law.
Children
Tally is a business tool and is not directed to anyone under 16. We do not knowingly collect data from children.
Changes to this policy
We may update this policy from time to time. We will revise the “Last updated” date above and, for material changes, notify you in the app or by email.
Contact
Questions about this policy or your data? Contact support@tally-works.com. See also our Terms of Service and Legal Notice.