The short version
- Tally Tame is a finance app. It holds your financial records so that you can see them in one place.
- We collect only what the app needs to work, to bill you, to keep your account safe, and to obey the law.
- We do not sell your personal information. We do not rent it. We do not use it for advertising.
- The site and the app use first-party, cookieless measurement that we host ourselves. It loads no script from another company, sets no cookie, cannot identify you across months and never goes to another company. We run no advertising tracker.
- Bank sign-in happens in Plaid's own flow. We never see or store a bank password. Access is read-only.
- Two-step verification uses an authenticator app or a text message. If you choose a text message, we collect your mobile phone number and use it only to send sign-in codes. Mobile phone numbers and text-message consent are used only to send sign-in verification codes. They are not sold, and they are not shared with third parties or affiliates for marketing purposes.
- Lines read from a receipt stay inside your workspace. We never compare what you buy with what anyone else buys.
- We store your records on servers in Toronto, Canada. Files you upload are stored in eastern North America. Some of our suppliers process data in the United States. Section 9.3 lists them.
- Receipt and statement scanning sends the image to an AI model at a third-party supplier. Section 6 explains what that means.
- No email, notification, push message or text message ever contains an amount from your records. Only billing email states a price.
- You can export everything you own and delete your account at any time, without asking us.
- Our privacy officer answers at privacy@tallytame.com within 30 days.
- Tally Tame is not offered today to residents of Quebec, the European Economic Area, the United Kingdom or Switzerland. Section 16 explains.
Who we are and how to reach us
Pixibiz Digital Inc. is a corporation in Ontario, Canada. It is the organization responsible for your personal information. Some countries' laws call this role the "controller".
- Role
- Legal name
- Detail
- Pixibiz Digital Inc.
- Role
- Mailing address
- Detail
- 812 Lansdowne Avenue, #514, Toronto, Ontario M6H 4K5, Canada
- Role
- Privacy officer
- Detail
- Johan Teran, Founder. This person is also the "person in charge of the protection of personal information" under Quebec law.
- Role
- Privacy email
- Detail
- privacy@tallytame.com
- Role
- Support email
- Detail
- support@tallytame.com
Write to the privacy email for any question, request or complaint about this policy. We answer within 30 days. If a request is complex, we tell you why we need more time and when to expect an answer.
Words used in this policy
- Personal information means information about an identifiable person. In this policy it includes your financial records.
- Financial records means the accounts, transactions, expenses, debts, budgets, goals, assets, receipts, receipt lines, items and statements in a workspace.
- Workspace means the container that holds one set of books. A person owns one or more workspaces.
- Member means a person who has joined a workspace with a role: owner, editor or viewer.
- Supplier means a company that processes personal information for us and on our instructions. Privacy laws call this a "processor" or "service provider".
- You means the person who uses Tally Tame or visits our site.
Information we collect
We collect information from 6 sources. This section lists each source and what it gives us. Section 4.7 covers data that is about nobody.
4.1Information you give us
Account information. Your email address, your first name, your last name, your password, your two-step verification secret, and a profile picture if you add one. We store your password as a hash, never in clear text. We store the two-step secret and the recovery codes encrypted. We never send a password by email.
Mobile phone number. Every account uses two-step verification. You choose an authenticator app or a text message. If you choose a text message, we collect your mobile phone number. We use it only to send a 6-digit sign-in code when you sign in or when you change the number. The only other message we ever send to it is a reply to HELP. A code expires after 3 minutes. We store the number once and show it only as its last 4 digits. Before the first text, you consent with a separate, unticked checkbox. We record the consent with its date and version, and we record a withdrawal, never delete it. Section 19 states the consent wording, how to stop texts, and who carries them. Mobile phone numbers and text-message consent are used only to send sign-in verification codes. They are not sold, and they are not shared with third parties or affiliates for marketing purposes.
Workspace information. The name, type (personal or business), currency, time zone, fiscal year start and default tax place of each workspace. A business workspace can carry a logo. A business workspace can also state whether it is registered for GST/HST and whether it is registered for QST. The 2 answers decide what part of a receipt's sales tax the workspace can treat as recoverable. Only the owner can change them. A personal workspace is never asked.
Financial records. Everything you type or import into a workspace. This includes accounts and their balances, transactions, expenses and their categories, splits and sales tax. Sales tax is kept as the named parts a receipt prints, such as GST and QST, with the place the purchase was made for tax purposes, and a tip when the slip shows one. It includes debts and their interest terms, budgets, goals, assets and their valuations. It includes reimbursements, shares between members, mileage and per-diem claims, recurring series, and rules. A transaction can carry a foreign-currency original amount.
Receipt lines and items. When a receipt is read, we store each line printed on it. A line holds the description as printed, the quantity, the line amount and the tip. Each line is matched by its name to an item in your own workspace. The item shows how often and at what cost you buy it. A tie is left unmatched. You can switch "Keep these items" off on the review dialog. Receipt lines and items stay inside the workspace they belong to. We never share them across workspaces or between people. We never use them to compare prices between people, and never for advertising. They are in the workspace export and are erased with the workspace.
Receipts, statements and photos. Receipt images you upload, photograph or forward by email. Statement files in PDF or image form that you upload for reading. Photos you attach to assets. We keep the AI reader's raw answer with the receipt or statement it belongs to, for fault finding. It is erased with that record. No staff screen shows its contents.
Imported statement files. CSV, TSV, OFX and QFX files are read inside your browser. The file itself is never uploaded. Only the rows you confirm reach our server. We remember your column mapping per bank so that you do not map it twice.
Support messages. What you write to us by email and the details you include.
Preferences. Your notification settings, your dashboard layout, and similar settings.
Do not enter government identification numbers, full card numbers or bank passwords into any field. Tally Tame does not need them and does not ask for them.
4.2Information from your bank through Plaid (Premium)
When you connect a bank, you sign in to your bank inside Plaid's own flow. Plaid Inc. then sends us the account details and the transactions for the accounts you chose. For each account: its name, type, masked number, currency, balance and available balance, and for a credit account its limit. Plaid does not send an interest rate; you can type one in. For each transaction: the date, description, merchant, amount, currency, a pending flag and a category hint. We translate the category hint into our own category words, and drop it unless Plaid reports high confidence. We keep no location and no counterparty details.
We also keep a small fixed extract of Plaid's own record of each transaction, for one purpose: to find out why an import went wrong. It holds Plaid's identifiers, the original amount and currency, the dates, the pending flag and the payment channel. It also holds the bank's transaction code, Plaid's category, the merchant identifier and the merchant category code. Nothing else from Plaid is kept. A field Plaid adds later is not kept unless we add it to this list. The extract is erased with the transaction.
The same fields are collected for a bank in Canada and a bank in the United States.
We hold a read-only access token for each connection. We never see or store your bank password. We cannot move money. Section 8 explains Plaid in detail.
4.3Information other members add about you
A workspace can have more than 1 member. Another member can record an expense you paid, a share you owe, or a settlement between you. That record is personal information about you. The workspace owner decides who is a member and what each member can see.
4.4Information from people who email receipts
A workspace has a receipt email address. It accepts mail only from verified members and from up to 10 senders that the owner lists. From an accepted email we keep only the attachment. We discard the sender, the subject and the body. We discard mail from any other sender. We log every delivery, accepted or refused, for 90 days. The log holds the outcome, a reason code, the attachment count and a hash of the message identifier. Mail to a receipt address passes through our email supplier before it reaches us.
4.5Information collected automatically
Session information. A session cookie that keeps you signed in. Your IP address, browser type and operating system reach our server with every request. We do not keep them, except a hashed address after a failed sign-in.
Referral cookie. Tally Tame has a referral programme. Each member has a referral code and a link. If you open a member's link, a cookie named tallytame.ref stores that code for 30 days. We read the cookie once, when you create an account, to credit the referral. Scripts cannot read it. It does not track you. If you arrive any other way, it is never set. You can also enter a member's code yourself, in Settings, Plan, within 14 days of creating your account. That path sets no cookie.
The referrer sees 2 counts: friends who joined, and rewards earned. The referrer never sees your name, your email address, your plan or a payment. You see only the code you used. Nobody outside Tally Tame receives anything about a referral. Section 16.4 describes the reward.
Text-message delivery records. For every text we send, we keep the date and the delivery outcome. We keep your number with all but the last 4 digits masked. We keep no message content. Our text-message supplier reports the delivery outcome to us.
Server logs. The app keeps no request log. The server keeps at most 30 MB of error output per app and overwrites it as it fills, in practice within days. A failed sign-in is recorded as a hashed address for 90 days.
Activity log. Each workspace records every change with who made it and when. It never records an amount. Entries expire after 1 year by default.
Push subscription. If you turn on push notifications, your browser gives us a subscription address and encryption keys. We store them so that we can send you messages. We encrypt every message before it leaves our server, by the web push standard (RFC 8291). The push service of your browser maker carries the message but cannot read it.
Device storage. The installed app caches only its offline page. It stores your sign-in session and your display preferences. No financial record is stored on your device. Sign-out clears the app's local preferences, except the theme.
Measurement. The site and the app measure use with Umami, an open-source analytics engine that we run ourselves on our own server in Toronto. It has no public address. Your browser sends each measurement only to our app. Our app checks it and passes it to the engine over an internal network. No script from another company loads. No measurement goes to another company. No supplier is involved, beyond the encrypted backups in section 10.
For each page view or event we record:
- The screen name, with every identifier removed before it leaves your browser. We record "accounts.detail", never the address of a specific account. Our server refuses anything that still carries an identifier.
- The referring site (domain only), the campaign tags on a link to the marketing site, and your browser, operating system, device type, screen size and language.
- Your country, region and city, derived on our server from your IP address with a local database. The IP address itself is not stored.
- A visitor number: a hash of your IP address and browser under a secret salt that changes every month. The same person is a different number next month. The number is never linked to an account.
- Named events from a fixed list: sign-up completed, address verified, two-step enrolled, workspace created, first account added, first expense added, bank connected, receipt uploaded, trial started, subscription started, subscription ended, referral qualified, and a click on the sign-up button on the marketing site. An event can carry only a category value, such as the workspace type or the plan name. An amount cannot be recorded. The list is enforced in code and by tests.
Measurement sets no cookie. It records no user identifier, no email address, no page address with an identifier in it, no page content, no amount, no balance, no financial record and no precise location.
If your browser sends the "Do Not Track" or the Global Privacy Control signal, you are not measured at all. Our server discards the measurement before reading it.
Staff see the result in the staff portal, as counts and charts only. The same screen shows counts from our own database: active accounts per day, how many people from a sign-up week came back, use per module, and trials that converted. Every figure is a count. No staff screen shows an individual visitor.
We do not run advertising trackers. We do not load scripts from other companies. We do not collect precise location.
4.6Payment information
Stripe, Inc. handles payment. When you buy Premium, you enter your card on a page that Stripe hosts. We never receive your full card number. From Stripe we store a customer identifier and your plan: its status, billing interval, price, currency, period and trial dates. We also store the identifiers of your invoices, with links to Stripe's hosted invoice and PDF. We do not store the card brand, the last 4 digits, the expiry or a billing address. Stripe holds them. Stripe's privacy policy is at https://stripe.com/privacy.
4.7Sample data and templates
Sample data is a made-up household. It contains no real person. Workspace templates shape an empty workspace with categories and a budget structure. They never contain an invented amount.
Why we use your information
We use personal information only for the purposes in this table. In Canada the basis for every purpose is your consent. You give it when you create an account, connect a bank, upload a receipt or turn on a feature. You can withdraw consent at any time (section 15). The last column names the legal basis in the words that some other countries' laws use.
- Purpose
- Provide the app: store your records, calculate balances, budgets, interest, payoff plans, forecasts and reports
- Information used
- Account, workspace and financial records
- Legal basis
- Contract
- Purpose
- Sync bank transactions and put them in your inbox to confirm
- Information used
- Plaid data, your rules
- Legal basis
- Contract, with your separate consent to connect
- Purpose
- Read receipts and statements with an AI model and prefill fields for you to confirm
- Information used
- Receipt and statement images
- Legal basis
- Consent, given when you use the feature
- Purpose
- Keep the lines of a receipt and match each one to an item in your workspace, so you can see how often and at what cost you buy it
- Information used
- Receipt lines, the items in your workspace
- Legal basis
- Contract. "Keep these items" is a switch on the review dialog.
- Purpose
- Send a 6-digit sign-in code by text message, if you chose text-message verification
- Information used
- Mobile phone number
- Legal basis
- Consent, given with a separate checkbox before the first text. Withdraw it by replying STOP or by removing the number.
- Purpose
- Suggest a category and a tag for an imported row
- Information used
- Your rules, your history for that merchant, a built-in keyword table
- Legal basis
- Contract
- Purpose
- Detect subscriptions, recurring expenses and unusual expenses in your own records
- Information used
- Your expenses and transactions
- Legal basis
- Contract
- Purpose
- Let members of a workspace work together under the roles and permissions the owner set
- Information used
- Member details, financial records
- Legal basis
- Contract
- Purpose
- Show market prices and exchange rates as estimates
- Information used
- Ticker symbols and currencies only
- Legal basis
- Contract
- Purpose
- Send notifications you turned on, a daily digest, planning alerts and reminders
- Information used
- Contact details, preferences, calendar entries
- Legal basis
- Contract, and consent for push
- Purpose
- Credit a referral and grant the reward to both sides
- Information used
- The referral code, the date you created your account, and the date of your first payment
- Legal basis
- Contract. You opt out by not using a code or a link.
- Purpose
- Measure how the site and the app are used, as counts: which screens are visited, where visitors come from, which steps of sign-up are completed
- Information used
- Measurement records (section 4.5). They are never linked to your account.
- Legal basis
- Legitimate interest in understanding and improving the product. A "Do Not Track" or Global Privacy Control signal opts you out.
- Purpose
- Send security notices about your account
- Information used
- Contact details, session information
- Legal basis
- Legitimate interest in the security of your account. These notices cannot be silenced.
- Purpose
- Bill you and issue invoices
- Information used
- Payment information from Stripe
- Legal basis
- Contract, and legal obligation for tax records
- Purpose
- Keep your account safe: two-step verification, breach checks on passwords, rate limits, lockouts
- Information used
- Account and session information
- Legal basis
- Legitimate interest in security, and legal obligation to protect personal information
- Purpose
- Find and stop abuse, fraud and attacks on the service
- Information used
- Session information, failed sign-in records, error output
- Legal basis
- Legitimate interest in a working and lawful service
- Purpose
- Answer support requests
- Information used
- Support messages, account information
- Legal basis
- Contract
- Purpose
- Send marketing email about Tally Tame. We send none today. If we start, we ask for a separate opt-in first.
- Information used
- Email address, marketing choice
- Legal basis
- Consent. You can withdraw it in 1 click.
- Purpose
- Obey the law, answer lawful requests, establish or defend legal claims
- Information used
- Any of the above, as required
- Legal basis
- Legal obligation, legitimate interest
To have an account you must give an email address and a password. Everything else is optional. Without a bank connection there is no bank sync. Without a receipt there is no scan. Without an email address there is no account.
The app asks for your consent in the moment at 3 points: the first bank connection, the first reading of a receipt or statement, and the first text message. It records each consent with the version of this policy. You can withdraw any of the 3 consents in Settings. Settings, Data and privacy, lists each consent with its date. Sign-up records your acceptance of this policy and of the terms, with the version and the time.
We do not use your personal information to train AI models. We do not build advertising profiles. We do not make decisions about you that have legal effect on you without a human.
We never use financial records for a purpose you did not expect. A "purpose you did not expect" includes selling them, scoring you, ranking you against other people, or sending them to an advertiser.
Features that use an AI model
Receipt scanning and statement reading use a vision model. The model runs at a third-party supplier. This section says exactly what happens.
- What is sent. The receipt image or statement file you chose, downscaled in your browser. With it, a short instruction that asks the model to find the merchant, its address, the amount, the date, the tax total, each tax line printed, and the lines printed.
- Who receives it. OpenRouter, Inc. (United States), which routes the request to an AI model provider. Today that provider is Google. Every request instructs OpenRouter to use only providers that neither keep nor train on the data.
- What comes back. Suggested values for you to confirm. For a receipt, the merchant, its address, the amount, the date, the tax total, each tax line the receipt prints, and the lines printed on it (section 4.1). The address proposes the place the purchase was made for tax purposes. The expense keeps only that place, at province or state level, never the address. For a statement, its transactions; every prefilled field carries a confidence, and anything uncertain is badged "Check this". Nothing is written to your books until you confirm it.
- The consent you give. Before the first read, the app asks for your consent. The consent describes the recipient as a third-party AI service and points to this section. This section is the place that names the supplier and the model provider, and it is versioned, so the name is always current. One consent covers receipts and statements.
- Training. We do not use your images or text to train a model. Our supplier's setting that blocks providers that train on data is on, and every request requires zero data retention.
- Your choice. You do not have to scan. You can type a receipt, or import a CSV that never leaves your browser.
- Limits on the Free plan. 5 scans a month.
A scan is a suggestion. It is not a decision about you. You can change every field before you save it.
Automated features that work on your records
Tally Tame runs several automated features on your own records, for you. None of them profiles you for advertising. None of them decides anything that has legal effect on you. Each one produces a suggestion, an estimate or a notice that you can change, dismiss or ignore.
- Feature
- Rules engine
- What it does
- Categorises, renames and can auto-confirm synced lines by rules you wrote
- Your control
- You write, edit and delete the rules. Each rule is on or off.
- Feature
- Category suggestions
- What it does
- Proposes a category for an imported row
- Your control
- You confirm each row. Auto-accept is a switch per workspace, off by default.
- Feature
- Item matching
- What it does
- Matches a line read from a receipt to an item in your workspace by its name. A tie is left unmatched.
- Your control
- You edit or unmatch any line. "Keep these items" is a switch on the review dialog.
- Feature
- Tax place
- What it does
- Proposes the place a purchase was made from the merchant's address on the receipt, or from the workspace's default place
- Your control
- You choose any place on the expense.
- Feature
- Receipt reconciliation
- What it does
- When you record a payment from a confirmed receipt and your bank later sends the same purchase within 7 days for the same amount to the cent, keeps 1 record and lets the bank's figure win
- Your control
- When it is not sure, it inserts the bank line, keeps yours, and asks you. Nothing is deleted without you. The notice it sends counts receipts and states no figure.
- Feature
- Subscription detection
- What it does
- Finds repeating charges in your expenses
- Your control
- You confirm or dismiss each finding. The owner can switch it off in workspace settings.
- Feature
- Anomaly sweep
- What it does
- Flags an expense that does not match your usual pattern
- Your control
- You dismiss a finding. The owner can switch it off in workspace settings.
- Feature
- Planning alerts (Premium)
- What it does
- Warns when a budget or a forecast crosses a line you set
- Your control
- You set and remove the lines and the notifications
- Feature
- Forecast
- What it does
- Walks your cash day by day for 30, 60 or 90 days from what is on file
- Your control
- It is an estimate. It records nothing.
- Feature
- Interest, minimum payment and payoff
- What it does
- Calculates from the terms you entered, and discloses the method
- Your control
- You edit the terms
- Feature
- Depreciation and market prices
- What it does
- Shows an estimate that never moves net worth until you record it
- Your control
- You decide what to record
Quebec law asks us to tell you about technology that can identify, locate or profile you. Tally Tame does not collect your precise location. Measurement (section 4.5) derives a country, region and city from your IP address, never links it to your account, and stops if your browser sends "Do Not Track". Tally Tame does not identify you across other sites or apps. The features above analyse only the records inside your own workspace, for you. The table says where each switch is. Forecast, interest, depreciation and market prices have no switch because they record nothing.
Bank connections through Plaid
Bank sync is a Premium feature. It uses Plaid Inc. ("Plaid"). This is how it works and what it means for your information.
- You choose your bank inside Plaid's hosted flow, on Plaid's screens.
- You sign in to your bank on those screens. Your bank password goes to Plaid and to your bank. It never reaches Tally Tame.
- Plaid gives us a read-only access token for the accounts you chose.
- We ask Plaid for new transactions when Plaid tells us that new lines exist. A sync is not instant.
- New lines land in your inbox to confirm as expenses.
When you connect a bank you give Plaid and Tally Tame the right to access and transmit your information from your bank, on your behalf. Plaid's own privacy policy governs what Plaid does with that information. Read it at https://plaid.com/legal/#end-user-privacy-policy. Plaid stores data in the United States.
You can disconnect a bank at any time in the app. That revokes our token at Plaid at once. Transactions already in your books stay until you delete them. To see and remove the connections Plaid holds for you, use the Plaid Portal at https://my.plaid.com. To see or delete what Plaid holds, use Plaid's data request form at https://my.plaid.com/data-subject-request-form or write to privacy@plaid.com. Both serve people in Canada and in the United States.
Bank sync is available for banks in Canada and in the United States. The country you gave at sign-up decides which country's banks you are offered. You cannot connect a bank in the other country. You can correct your country in Settings. A correction re-checks whether you may use Tally Tame (terms of service, section 3). A bank already connected stays connected when you correct your country.
Who can see your information
9.1Members of your workspace
Members see what the owner allows. The owner sets a role (owner, editor, viewer) and per-member module permissions: accounts, debts, expenses, budgets, goals, assets, reports. Export is a separate permission. An editor can change or delete records, including records about you. If you leave a workspace, the records you entered stay in the workspace. The activity log shows who changed what.
Think before you invite. A member you add can see everything that their permissions allow.
9.2People you authorise
You can create a personal access token and give it to software you trust. The token is read-only and is scoped to the modules you choose. The software then sees the same rows that the CSV export defines. You can revoke a token at any time. A token dies with your membership.
9.3Our suppliers
The companies below process personal information for us, on our instructions, and only for the purpose stated. A data processing agreement is in force with every supplier: 6 by incorporation into their terms, and Plaid under its master agreement. We do not permit them to use your information for their own purposes. None of them receives your full financial records except where the table says so.
- Supplier
- DigitalOcean, LLC
- Purpose
- Hosting of the app server and the database
- Location of processing
- Toronto, Canada. The company is in the United States.
- What it receives
- All data in the app, encrypted at rest
- Supplier
- Cloudflare, Inc.
- Purpose
- File storage and our daily backup copy
- Location of processing
- Eastern North America, every bucket
- What it receives
- Receipts, statements, photos, profile pictures and workspace photos (private bucket); organization logos (public bucket); an encrypted daily copy of the database and of the private bucket (backup bucket, kept 30 days)
- Supplier
- Plaid Inc.
- Purpose
- Bank connections (Premium)
- Location of processing
- United States
- What it receives
- Bank account and transaction data for the accounts you connect. Privacy policy: https://plaid.com/legal/#end-user-privacy-policy
- Supplier
- Stripe, Inc.
- Purpose
- Billing
- Location of processing
- United States and worldwide
- What it receives
- Email, card details you enter on Stripe's page, plan and invoices. Privacy policy: https://stripe.com/privacy
- Supplier
- OpenRouter, Inc. and the AI model provider it routes to
- Purpose
- Reading of receipts and statements. Also reading of published government sales tax rate pages, which contain no personal information.
- Location of processing
- United States
- What it receives
- The image or file you chose to scan, with no other record
- Supplier
- Resend, Inc.
- Purpose
- Sending email, and receiving mail sent to a receipt address
- Location of processing
- United States
- What it receives
- Your email address, the subject and body of each email we send, and receipt email before we file the attachment
- Supplier
- Telnyx LLC
- Purpose
- Sending sign-in codes by text message, if you chose text-message verification
- Location of processing
- United States (Chicago)
- What it receives
- Your mobile phone number and the text of the code. It reports back whether the text was delivered.
- Supplier
- GitHub, Inc.
- Purpose
- Build and storage of our software images
- Location of processing
- United States
- What it receives
- No personal information
- Supplier
- Finnhub
- Purpose
- Market prices
- Location of processing
- United States
- What it receives
- Ticker symbols only. No personal information.
- Supplier
- Bank of Canada Valet
- Purpose
- Exchange rates
- Location of processing
- Canada
- What it receives
- Currency codes only. No personal information.
- Supplier
- Browser push services (Google, Apple, Mozilla)
- Purpose
- Delivery of push notifications
- Location of processing
- Worldwide
- What it receives
- An encrypted message they cannot read, and your subscription address
We do not use Flinks or any other bank data provider.
9.4Our staff
Tally Tame has a staff portal. Access requires two-step verification. Every change a staff member makes is audited. Staff look at your records only to answer a request you made, to fix a fault, or to investigate abuse. Every lookup of an account by staff is logged. Today 1 person has that access.
For customer support, a staff member with the organisation-manager role or higher can look up an account by email address or name. The lookup shows: your name, your email address and whether it is verified; when the account was created; your locale and time zone; your country and region; the versions of the terms and of this policy you accepted and when; whether two-step verification is on and since when; whether the account is locked after failed sign-ins; the number of active sessions and the country and city of the newest one; your plan and subscription status; the workspaces you belong to, with your role and the member count; the consents you gave or withdrew; your referral code and counts; and your notification channel preferences.
The lookup never shows a balance, a transaction, an expense, a receipt or an amount. It never shows a password, a two-step secret, a recovery code or a session token.
Every lookup is written to the staff audit log: who looked, at whom, and when. Staff can also end your sessions, clear a sign-in lockout, and write a support note. Each of those actions is logged. Resetting two-step verification and closing an account are not portal actions. A staff member runs them by command on the server, after confirming your identity through a second channel.
9.5When the law requires it
We disclose personal information when a law, a court order or a lawful request from a public authority requires it. We check every request. We tell you about it when the law allows us to.
9.6If the business changes hands
If Pixibiz sells Tally Tame, merges, or becomes insolvent, your information can pass to the new operator. We tell you by email before that happens, at least 30 days ahead where the law allows it. The new operator must honour this policy or give you a way to delete your account first.
9.7What we never do
We never sell personal information. We never rent it. We never share financial records with an advertiser, a data broker, a credit bureau, a lender or an insurer. We never receive a fee or a benefit for your information. No such arrangement exists. Mobile phone numbers and text-message consent are used only to send sign-in verification codes. They are not sold, and they are not shared with third parties or affiliates for marketing purposes. We never use the lines of your receipts to compare prices between people.
Where your information is stored
Canada. The app server and the database are in Toronto, Ontario. Files you upload (receipts, statements, photos, logos and profile pictures) are stored with Cloudflare in eastern North America. The database is a managed cluster, encrypted at rest, reachable only from the app server over an encrypted connection. Backups are encrypted. Every day we also take an encrypted copy of the database and of your files to a separate Cloudflare storage location in eastern North America. We keep each daily copy for 30 days. Measurement records (section 4.5) are in a database of their own on the same cluster in Toronto, and the backups above cover them.
Outside Canada. The suppliers in section 9.3 process some information in the United States. When personal information is in another country, the courts, police and security agencies of that country can require access to it under their own laws. We remain responsible for your information while a supplier holds it.
If you live outside Canada. Your records are stored in Canada all the same. Canadian law governs how we hold them there, and the authorities of Canada can require access to them under Canadian law.
Suppliers' own transfer safeguards. Some suppliers hold a certification under the EU-US Data Privacy Framework, or sign standard contractual clauses. Where they do, we rely on it in addition to Canadian law. Write to us for a copy of a supplier's clauses.
How long we keep your information
We keep personal information only as long as this table says. After that we delete it or make it anonymous.
- Information
- Account, workspaces and financial records
- How long
- While your account exists, then 30 days after you delete the account. During the 30 days you can undo the deletion. After that we erase everything, files included.
- Information
- A deleted workspace
- How long
- 7 days, then erased
- Information
- A deleted account (single account inside a workspace)
- How long
- Removed at once. Expenses linked to it are kept.
- Information
- Receipts, statements and photos
- How long
- Same as the record they belong to
- Information
- Receipt lines and the items they build
- How long
- Same as the workspace they belong to
- Information
- The tax parts of an expense, and the workspace's tax settings
- How long
- Same as the workspace they belong to
- Information
- Mobile phone number, text-message consent and opt-out
- How long
- While your account exists, then erased with it
- Information
- Text-message delivery records (date, outcome, masked number)
- How long
- While your account exists, then erased with it
- Information
- Activity log entries
- How long
- 1 year by default, then expired
- Information
- Financial history on the Free plan
- How long
- Records older than 12 months are kept, not deleted. The Free plan does not show them. Premium shows them again.
- Information
- Sample data
- How long
- Until you remove it, in 1 action
- Information
- Sessions
- How long
- Until expiry, 30 days from your last use
- Information
- Failed sign-in attempts (hashed address)
- How long
- 90 days
- Information
- Server error output
- How long
- Overwritten as it fills, in practice within days. There is no request log.
- Information
- Scheduled job ledger
- How long
- 1 year. It holds no financial record.
- Information
- Scan usage ledger (a count per scan, no image)
- How long
- 1 year
- Information
- Provider webhook events (Stripe, Plaid)
- How long
- 90 days
- Information
- Receipt email delivery log
- How long
- 90 days
- Information
- Push subscriptions
- How long
- Until you turn push off, or the browser cancels the subscription
- Information
- Personal access tokens
- How long
- Until you revoke them, or your membership ends
- Information
- Referral code, referral counts and rewards
- How long
- While your account exists
- Information
- Measurement records (section 4.5)
- How long
- For as long as we run the service, then deleted. They cannot identify you, and the purpose, measuring the product over time, does not end.
- Information
- Support notes written by staff about your account (section 9.4)
- How long
- While your account exists, then erased with it
- Information
- Staff audit log: who looked at or acted on an account, and when (section 9.4)
- How long
- For as long as we run the service. It is the record of what staff did. It holds no financial record.
- Information
- Support email
- How long
- 3 years after the last message in the thread
- Information
- Billing records at Stripe and our copies
- How long
- 6 years after the end of the tax year, as Canadian tax law requires
- Information
- Email logs at our email supplier
- How long
- 30 days at Resend
- Information
- Records of a privacy breach
- How long
- 5 years. Canadian federal law requires 24 months and Quebec law requires 5 years.
- Information
- Backups
- How long
- The hosting supplier keeps 7 days of database backups. Our own daily copy of the database and files is kept for 30 days. A deleted record can persist in a backup for up to 30 days.
If a law requires us to keep a record longer, or a legal claim is open, we keep only what that requires.
How we protect your information
These are the measures we run today.
- We require two-step verification for every account, by authenticator app or by text message. You enrol during sign-up. We issue recovery codes. The authenticator app is the safer choice: a text message can be moved to another phone by somebody who tricks a mobile operator.
- A text-message code is 6 digits, expires after 3 minutes and allows 5 attempts. Codes are stored hashed. Changing the number takes your password and a live code, and is confirmed by a code sent to the new number.
- Every connection uses TLS 1.2 or 1.3 with HSTS.
- The database is encrypted at rest with keys that the hosting supplier holds. Backups are encrypted.
- The server checks your access on every request. A test enumerates every endpoint against another workspace's identifiers.
- We check passwords against known breach lists. We rate limit sign-in and lock it per account. The lockout never reveals whether an address exists.
- We identify uploaded files by their bytes, strip their metadata, and serve them only through a membership check.
- No amount from your records ever appears in an email, a notification, a push message or a text message. The build enforces this.
- No advertising tracker and no script from another company runs in the app. The only measurement is the first-party, cookieless measurement in section 4.5, which runs on our own server and never leaves it.
- Staff access uses a separate portal with mandatory two-step verification and an audit of every change and of every lookup of an account.
No system is perfectly secure. We do not promise that a breach cannot happen. We promise what section 13 says.
If a breach happens
If we learn that personal information was lost, stolen or accessed without permission, we act at once.
- We contain the breach and record it in our breach register.
- If the breach creates a real risk of significant harm to you, we notify you as soon as feasible. In Quebec the test is a risk of serious injury. We use email and an in-app notice. We tell you what happened, what information was involved, what we did, and what you can do.
- We report the breach to the Office of the Privacy Commissioner of Canada. We also report it to any other regulator the law names.
- We notify a bank, Plaid or another organization when that helps reduce the harm.
Your choices and controls
You control most of this without writing to us.
- To
- See everything you own
- Do this
- Export a CSV, a workspace ZIP with a manifest, or an archive of your whole account. No request to staff, no waiting.
- To
- Delete your account
- Do this
- Choose delete in settings. You have 30 days to change your mind. Then we erase everything.
- To
- Delete a workspace
- Do this
- Choose delete. You have 7 days to change your mind.
- To
- Disconnect a bank
- Do this
- Remove the connection in the app. The token is revoked at once.
- To
- Stop a scan feature
- Do this
- Do not use it. Type the receipt or import a file instead.
- To
- Change notifications
- Do this
- Set preferences per category, per workspace and for the daily digest. Security notices stay on.
- To
- Turn off push
- Do this
- Turn it off in the app or in your browser settings.
- To
- Stop text messages
- Do this
- Reply STOP to any text, or remove your number in Settings. Sign in with your authenticator app or your recovery codes instead. Two-step verification stays on.
- To
- Stop keeping receipt lines
- Do this
- Switch off "Keep these items" on the review dialog. Delete any line or item in the workspace.
- To
- Stop marketing email
- Do this
- We send none today. If we start, every marketing email has an unsubscribe link, and we act within 10 business days. Service and security email continues, because it is part of the service.
- To
- Revoke a personal access token
- Do this
- Delete it in settings.
- To
- Remove a member
- Do this
- The owner removes the member. Their access ends at once.
- To
- Leave a workspace
- Do this
- Leave from the workspace settings.
- To
- Clear the app from your device
- Do this
- Sign out. That clears the app's local preferences, except the theme. No financial record is on your device. Remove the installed app yourself if you want it gone.
- To
- Refuse cookies
- Do this
- The app uses 2 cookies (section 18). Block the session cookie and you cannot sign in. Block the referral cookie and everything works, but a referral is not credited.
Your rights
Wherever you live, you have these rights over your personal information. Some laws name them differently. We honour them for everyone.
- Access. Ask what personal information we hold about you and get a copy. The export in the app gives you your records at once. Write to us for anything else.
- Correction. Fix any inaccurate or incomplete information. You can edit your records in the app. Write to us for anything else.
- Deletion. Delete your account in the app, or ask us to delete your information. We keep only what a law requires us to keep, and we tell you what that is.
- Portability. Receive your records in a structured, commonly used, machine-readable format. The CSV and ZIP exports do this. You can also ask us to send them to another organization where that is technically possible.
- Withdraw consent. Withdraw a consent you gave, at any time. Withdrawal does not undo what happened before it. Some features stop when you withdraw the consent they need.
- Object and restrict. Object to a use that rests on our legitimate interest, or ask us to restrict a use while we check a dispute.
- No automated decisions. We make no decision about you by automated means alone that has a legal or similar effect on you. If that ever changes, we tell you first and you can ask for a human review.
- Complain. Complain to us first. If you are not satisfied, complain to a regulator (section 16).
- No penalty. We never treat you worse because you exercised a right.
How to exercise a right. Write to the privacy email. Tell us what you want. We may ask you to confirm your identity from the email address on your account. We answer within 30 days. If we refuse a request in whole or in part, we tell you why and how to complain. We do not charge a fee unless a request is repetitive or excessive, and then we tell you the fee first.
Someone acting for you. An authorised agent can make a request for you. We ask for proof of the authorisation and we confirm with you.
Information for specific places
16.1Canada
The Personal Information Protection and Electronic Documents Act (PIPEDA) governs how we handle personal information. Where a province has its own private-sector privacy law, that law also applies to residents of that province.
You can complain to the Office of the Privacy Commissioner of Canada: https://www.priv.gc.ca, 1-800-282-1376.
16.2Quebec
Tally Tame is not offered to residents of Quebec today. The app, this policy and the terms of service exist only in English, and Quebec law requires French. Sign-up asks where you live and refuses Quebec. If we learn that an account belongs to a resident of Quebec, we tell the person. We give them 30 days to export their records, and then we close the account.
If you are a resident of Quebec and you hold an account despite that rule, Quebec law still protects you, and we apply it:
- The person in charge of the protection of personal information at Pixibiz is Johan Teran, Founder. Reach that person at the privacy email in section 2.
- We ask for your consent separately, in clear words, before we collect sensitive information such as a bank connection or a receipt. The request is not hidden in the terms of service.
- Your information is stored outside Quebec (section 10).
- The app's default settings give the highest level of confidentiality. Nobody sees a workspace until you invite them. Push is off until you turn it on. We send no marketing email.
- Section 7 describes technology that could be seen as profiling. Tally Tame does not collect your precise location and does not identify you across other services.
- We make no decision about you by exclusively automated means.
- You have a right to portability, to ask us to stop disseminating information, and to ask for de-indexing.
- You can complain to the Commission d'accès à l'information du Québec: https://www.cai.gouv.qc.ca.
We plan to offer Tally Tame in Quebec once a French version of the app and of these documents exists. This section changes at that time.
16.3European Economic Area, United Kingdom and Switzerland
Tally Tame is not offered to residents of the European Economic Area, the United Kingdom or Switzerland today. We have no representative there, and the law of those places requires one. Sign-up asks where you live and refuses those places. If we learn that an account belongs to a resident of one of them, we tell the person. We give them 30 days to export their records, and then we close the account.
If you hold an account despite that rule, you keep every right in section 15. You can also complain to the supervisory authority of your country of residence. In the UK that is the Information Commissioner's Office, https://ico.org.uk.
We do not collect special categories of personal information. A transaction description can reveal a sensitive fact about you, for example a payment to a clinic. We do not analyse, categorise or infer any such fact. We treat every transaction the same way.
16.4United States
This section is for residents of California and of other states with a consumer privacy law. We describe our practices in the terms those laws use.
Categories of personal information collected in the last 12 months, and the source.
- Category
- Identifiers
- Examples
- Email address, mobile phone number if you chose text-message verification, IP address, customer identifier at Stripe
- Source
- You, your browser, Stripe
- Category
- Customer records
- Examples
- First name, last name
- Source
- You
- Category
- Financial information
- Examples
- Accounts, balances, transactions, expenses, debts, budgets, goals, assets, receipt lines and items, sales tax parts
- Source
- You, other members, your bank through Plaid
- Category
- Commercial information
- Examples
- Plan, invoices, payment history
- Source
- Stripe
- Category
- Internet or network activity
- Examples
- Session information, failed sign-in records, measurement records (section 4.5)
- Source
- Your browser
- Category
- Geolocation data
- Examples
- Country, region and city derived from an IP address for measurement, never linked to an account. No precise location.
- Source
- Your browser
- Category
- Visual information
- Examples
- Receipt images, statement images, asset photos, an avatar
- Source
- You
- Category
- Inferences
- Examples
- A suggested category or tag for a transaction, a detected subscription
- Source
- Derived from your own records
- Category
- Sensitive personal information
- Examples
- Account sign-in credentials (as a hash), financial account information from Plaid
- Source
- You, Plaid
Purposes. Section 5. Disclosure to service providers. Section 9.3. Each supplier receives only the categories the table shows.
Sale and sharing. We do not sell personal information. We do not share it for cross-context behavioural advertising. We have not done either in the last 12 months. We have no plan to. We do not sell or share the personal information of anyone under 16, because nobody under 18 may use Tally Tame.
Sensitive personal information. We use it only to provide the service you asked for, to keep your account secure, and as the law permits. We do not use it to infer characteristics about you.
Opt-out preference signals. The app has no advertising and no sale or share to opt out of. We treat a Global Privacy Control signal as a valid request anyway. A browser that sends it receives an acknowledging header on every app page, and it is not measured at all (section 4.5).
Bank connections. If you connect a United States bank, Plaid handles your bank data in the United States under its end user privacy policy. You can see and remove the connections Plaid holds for you at https://my.plaid.com, and ask Plaid about its data through the form in section 8. We receive the same fields for a United States bank as for a Canadian bank (section 4.2).
Retention. Section 11 states how long we keep each category.
Notice of financial incentive. The referral programme is a financial incentive under California law, because it rewards an attributed sign-up. These are its terms.
- What you give. When you use a member's link or code, we record the code and the date you created your account. Later we record the date of your first Premium payment. Nothing else. The referrer sees only a count.
- What each side gets. The same number of days of Premium, 30 by default, for you and for the referrer. The reward is earned when you first pay for Premium, or at sign-up if we say so at the time. It is never money. A member who already pays for Premium receives the days as a credit against the next invoice.
- How to opt in. Open a member's link before you sign up. Or enter their code in Settings, Plan, within 14 days of creating your account.
- How to opt out. Do not use a link or a code. You can also ask us to remove a referral attribution at any time by writing to the privacy email. Removal ends any reward not yet used.
- The value of your information. We do not price personal information. We value the incentive at the cost of the days of Premium we give, 30 days at the Premium monthly price. That is the whole value we assign, and the method is the price list in the terms of service.
- If the programme ends. We can pause or end the programme. A reward already earned stays.
Your rights. Know, access, correct, delete, receive a portable copy, opt out of sale or sharing, limit use of sensitive personal information, and not be discriminated against. Section 15 says how to exercise them. We answer within 30 days, inside the 45 days that state law allows. If we refuse, you can appeal by replying to our answer. We answer the appeal within 30 days. If you still disagree, we tell you how to contact your state attorney general.
California "Shine the Light". We do not disclose personal information to third parties for their direct marketing purposes.
Children. We do not knowingly collect personal information from anyone under 13, or from anyone under 18. See section 17.
Washington My Health My Data Act. We do not collect consumer health data. We do not infer health from your transactions.
16.5Other countries
If you live somewhere not named above, the law of your country can give you rights beyond section 15. We honour them where they apply. Write to us.
Age
Tally Tame is for adults. You must be 18 or older to create an account. We do not knowingly collect personal information from anyone under 18. If we learn that we hold information about a person under 18, we delete the account and the information. If you believe that a minor has an account, write to the privacy email.
Cookies and device storage
Tally Tame uses only what it needs to work.
- Item
- Session cookie
- Purpose
- Keeps you signed in
- Lasts
- 30 days from your last use, or until you sign out
- Item
- Referral cookie (
tallytame.ref) - Purpose
- Records the referral link you arrived through, so that the referral is credited when you sign up. Set only when you arrive through such a link. Not readable by scripts.
- Lasts
- 30 days
- Item
- Preference storage
- Purpose
- Remembers your theme and layout
- Lasts
- Until you clear it or sign out. The theme stays after sign-out.
- Item
- App files cache
- Purpose
- Lets the installed app open when you are offline
- Lasts
- Until you remove the app or clear site data
- Item
- Push subscription
- Purpose
- Delivers notifications you turned on
- Lasts
- Until you turn push off
There is no advertising cookie, no analytics cookie and no third-party cookie. Measurement (section 4.5) sets no cookie. We honour "Do Not Track": a browser that sends it is not measured. None of the items above follows you to another site or app, so no cookie banner appears.
Email, notifications, push and text messages
Service messages. We send email that the service needs: sign-up confirmation, security notices, receipts for payment, invoices, notices about your plan, and notifications you turned on. These messages are part of the service. Security notices cannot be silenced.
Marketing messages. We send no marketing email today. If we start, we send it only to people who opted in. The opt-in is a separate, unticked choice. Every marketing email names Pixibiz Digital Inc., carries our mailing address, and has an unsubscribe link that works for at least 60 days. We honour an unsubscribe within 10 business days. This follows Canada's anti-spam law (CASL).
Push notifications. Push is off until you turn it on. You choose the categories. We send no marketing push. If we start, it requires a separate opt-in.
Text messages. If you chose text-message verification, we send a 6-digit code to your mobile phone number. We send it when you sign in or when you change the number. We send nothing else to it. A code expires after 3 minutes. Before the first text, you agree with a separate, unticked checkbox to this wording: "I agree to receive sign-in verification texts from Tally Tame. Reply STOP to opt out. Reply HELP for help. Standard message and data rates may apply. Message frequency may vary." Reply STOP to any text to end texts to that number. Reply HELP for help. We answer HELP by text message, even after you send STOP, because the mobile carriers require it. Replying STOP withdraws your consent and stops every text to that number. Reply START to receive codes again, if your consent is still on file. A word from a phone never restores a consent you withdrew in the app. You can also remove the number in Settings. After that, sign in with your authenticator app or your recovery codes. Two-step verification stays on. Our text-message supplier is Telnyx LLC (section 9.3). Your mobile carrier's standard message and data rates apply. Mobile phone numbers and text-message consent are used only to send sign-in verification codes. They are not sold, and they are not shared with third parties or affiliates for marketing purposes.
No amounts from your records. No email, notification, push message or text message ever contains an amount from your records. A person who reads your inbox or your lock screen sees that a payment is due. That person does not see how much. Billing email is the one exception: the purchase receipt, the yearly renewal reminder, the promotion-end notice and the price-change notice state the plan's price. We send billing email ourselves. Stripe's own emails are off.
Changes to this policy
We change this policy when the product, the law or our suppliers change. For a material change we email every account holder at least 30 calendar days before the change takes effect. We show a notice in the app until that date. At your first sign-in after that date, we ask you to accept the new version. A material change is one that expands what we collect, why we use it, or who receives it. For a change that needs your consent, we ask for it before the change applies to you. Each version carries its effective date and a summary of what changed.
- Version
- 1.0
- Date
- 2026-09-05
- Change
- First published version.
- Version
- 1.1
- Date
- 2026-09-14
- Change
- Two-step verification by text message: the mobile phone number we collect, the consent, STOP and HELP, delivery records, the supplier Telnyx LLC, and the carrier statement that numbers and consent are never shared for marketing (sections 1, 4.1, 4.5, 5, 9.3, 9.7, 11, 12, 14, 16.4, 19). Receipt lines and items kept inside the workspace (sections 1, 3, 4.1, 5, 6, 7, 9.7, 11, 14, 16.4). The AI reading consent covers statements as well as receipts and points to section 6 for the supplier's name (sections 5, 6). Revised on 2026-09-14, before publication, for the same release: HELP answered by text and START (4.1, 19); the reader also returns the merchant's address and each printed tax line, and the raw answer is kept with the receipt (4.1, 6); sales tax kept as named parts on every workspace, the tax place, and a business workspace's GST/HST and QST registration answers (4.1, 7, 11, 16.4); receipt reconciliation (7); OpenRouter also reads published government rate pages (9.3); the measurement event list completed (4.5). Revised again on 2026-09-14, the day bank sync went live, before any customer account existed: bank sync is live for banks in Canada and the United States, the sign-up country decides the banks offered, a country can be corrected in Settings (8); the account fields from Plaid corrected (no interest rate), the debugging extract disclosed and erased with the transaction, and the same fields in both countries (4.2); records of people outside Canada are stored in Canada (10); the Plaid Portal named (8, 16.4).