Skip to content
Tally Tame
WorkspaceDebt clarityCapturePersonal + business
Sign inStart free
Policy

Privacy policy

Pixibiz Digital Inc. ("Pixibiz", "we", "us") operates Tally Tame. This policy explains what personal information we collect and why. It says who can see it, where it goes, and what you can do about it. Read it together with the Tally Tame terms of service.

Effective 14 Sep 2026Version 1.149 min read
On this page
1The short version2Who we are and how to reach us3Words used in this policy4Information we collect5Why we use your information6Features that use an AI model7Automated features that work on your records8Bank connections through Plaid9Who can see your information10Where your information is stored11How long we keep your information12How we protect your information13If a breach happens14Your choices and controls15Your rights16Information for specific places17Age18Cookies and device storage19Email, notifications, push and text messages20Changes to this policy
Questions about this policy?Contact us
On this page
1The short version2Who we are and how to reach us3Words used in this policy4Information we collect5Why we use your information6Features that use an AI model7Automated features that work on your records8Bank connections through Plaid9Who can see your information10Where your information is stored11How long we keep your information12How we protect your information13If a breach happens14Your choices and controls15Your rights16Information for specific places17Age18Cookies and device storage19Email, notifications, push and text messages20Changes to this policy
1

The short version

  • Tally Tame is a finance app. It holds your financial records so that you can see them in one place.
  • We collect only what the app needs to work, to bill you, to keep your account safe, and to obey the law.
  • We do not sell your personal information. We do not rent it. We do not use it for advertising.
  • The site and the app use first-party, cookieless measurement that we host ourselves. It loads no script from another company, sets no cookie, cannot identify you across months and never goes to another company. We run no advertising tracker.
  • Bank sign-in happens in Plaid's own flow. We never see or store a bank password. Access is read-only.
  • Two-step verification uses an authenticator app or a text message. If you choose a text message, we collect your mobile phone number and use it only to send sign-in codes. Mobile phone numbers and text-message consent are used only to send sign-in verification codes. They are not sold, and they are not shared with third parties or affiliates for marketing purposes.
  • Lines read from a receipt stay inside your workspace. We never compare what you buy with what anyone else buys.
  • We store your records on servers in Toronto, Canada. Files you upload are stored in eastern North America. Some of our suppliers process data in the United States. Section 9.3 lists them.
  • Receipt and statement scanning sends the image to an AI model at a third-party supplier. Section 6 explains what that means.
  • No email, notification, push message or text message ever contains an amount from your records. Only billing email states a price.
  • You can export everything you own and delete your account at any time, without asking us.
  • Our privacy officer answers at privacy@tallytame.com within 30 days.
  • Tally Tame is not offered today to residents of Quebec, the European Economic Area, the United Kingdom or Switzerland. Section 16 explains.
2

Who we are and how to reach us

Pixibiz Digital Inc. is a corporation in Ontario, Canada. It is the organization responsible for your personal information. Some countries' laws call this role the "controller".

  • Role
    Legal name
    Detail
    Pixibiz Digital Inc.
  • Role
    Mailing address
    Detail
    812 Lansdowne Avenue, #514, Toronto, Ontario M6H 4K5, Canada
  • Role
    Privacy officer
    Detail
    Johan Teran, Founder. This person is also the "person in charge of the protection of personal information" under Quebec law.
  • Role
    Privacy email
    Detail
    privacy@tallytame.com
  • Role
    Support email
    Detail
    support@tallytame.com
Table 1 in section 2
RoleDetail
Legal namePixibiz Digital Inc.
Mailing address812 Lansdowne Avenue, #514, Toronto, Ontario M6H 4K5, Canada
Privacy officerJohan Teran, Founder. This person is also the "person in charge of the protection of personal information" under Quebec law.
Privacy emailprivacy@tallytame.com
Support emailsupport@tallytame.com

Write to the privacy email for any question, request or complaint about this policy. We answer within 30 days. If a request is complex, we tell you why we need more time and when to expect an answer.

3

Words used in this policy

  • Personal information means information about an identifiable person. In this policy it includes your financial records.
  • Financial records means the accounts, transactions, expenses, debts, budgets, goals, assets, receipts, receipt lines, items and statements in a workspace.
  • Workspace means the container that holds one set of books. A person owns one or more workspaces.
  • Member means a person who has joined a workspace with a role: owner, editor or viewer.
  • Supplier means a company that processes personal information for us and on our instructions. Privacy laws call this a "processor" or "service provider".
  • You means the person who uses Tally Tame or visits our site.
4

Information we collect

We collect information from 6 sources. This section lists each source and what it gives us. Section 4.7 covers data that is about nobody.

4.1Information you give us

Account information. Your email address, your first name, your last name, your password, your two-step verification secret, and a profile picture if you add one. We store your password as a hash, never in clear text. We store the two-step secret and the recovery codes encrypted. We never send a password by email.

Mobile phone number. Every account uses two-step verification. You choose an authenticator app or a text message. If you choose a text message, we collect your mobile phone number. We use it only to send a 6-digit sign-in code when you sign in or when you change the number. The only other message we ever send to it is a reply to HELP. A code expires after 3 minutes. We store the number once and show it only as its last 4 digits. Before the first text, you consent with a separate, unticked checkbox. We record the consent with its date and version, and we record a withdrawal, never delete it. Section 19 states the consent wording, how to stop texts, and who carries them. Mobile phone numbers and text-message consent are used only to send sign-in verification codes. They are not sold, and they are not shared with third parties or affiliates for marketing purposes.

Workspace information. The name, type (personal or business), currency, time zone, fiscal year start and default tax place of each workspace. A business workspace can carry a logo. A business workspace can also state whether it is registered for GST/HST and whether it is registered for QST. The 2 answers decide what part of a receipt's sales tax the workspace can treat as recoverable. Only the owner can change them. A personal workspace is never asked.

Financial records. Everything you type or import into a workspace. This includes accounts and their balances, transactions, expenses and their categories, splits and sales tax. Sales tax is kept as the named parts a receipt prints, such as GST and QST, with the place the purchase was made for tax purposes, and a tip when the slip shows one. It includes debts and their interest terms, budgets, goals, assets and their valuations. It includes reimbursements, shares between members, mileage and per-diem claims, recurring series, and rules. A transaction can carry a foreign-currency original amount.

Receipt lines and items. When a receipt is read, we store each line printed on it. A line holds the description as printed, the quantity, the line amount and the tip. Each line is matched by its name to an item in your own workspace. The item shows how often and at what cost you buy it. A tie is left unmatched. You can switch "Keep these items" off on the review dialog. Receipt lines and items stay inside the workspace they belong to. We never share them across workspaces or between people. We never use them to compare prices between people, and never for advertising. They are in the workspace export and are erased with the workspace.

Receipts, statements and photos. Receipt images you upload, photograph or forward by email. Statement files in PDF or image form that you upload for reading. Photos you attach to assets. We keep the AI reader's raw answer with the receipt or statement it belongs to, for fault finding. It is erased with that record. No staff screen shows its contents.

Imported statement files. CSV, TSV, OFX and QFX files are read inside your browser. The file itself is never uploaded. Only the rows you confirm reach our server. We remember your column mapping per bank so that you do not map it twice.

Support messages. What you write to us by email and the details you include.

Preferences. Your notification settings, your dashboard layout, and similar settings.

Do not enter government identification numbers, full card numbers or bank passwords into any field. Tally Tame does not need them and does not ask for them.

4.2Information from your bank through Plaid (Premium)

When you connect a bank, you sign in to your bank inside Plaid's own flow. Plaid Inc. then sends us the account details and the transactions for the accounts you chose. For each account: its name, type, masked number, currency, balance and available balance, and for a credit account its limit. Plaid does not send an interest rate; you can type one in. For each transaction: the date, description, merchant, amount, currency, a pending flag and a category hint. We translate the category hint into our own category words, and drop it unless Plaid reports high confidence. We keep no location and no counterparty details.

We also keep a small fixed extract of Plaid's own record of each transaction, for one purpose: to find out why an import went wrong. It holds Plaid's identifiers, the original amount and currency, the dates, the pending flag and the payment channel. It also holds the bank's transaction code, Plaid's category, the merchant identifier and the merchant category code. Nothing else from Plaid is kept. A field Plaid adds later is not kept unless we add it to this list. The extract is erased with the transaction.

The same fields are collected for a bank in Canada and a bank in the United States.

We hold a read-only access token for each connection. We never see or store your bank password. We cannot move money. Section 8 explains Plaid in detail.

4.3Information other members add about you

A workspace can have more than 1 member. Another member can record an expense you paid, a share you owe, or a settlement between you. That record is personal information about you. The workspace owner decides who is a member and what each member can see.

4.4Information from people who email receipts

A workspace has a receipt email address. It accepts mail only from verified members and from up to 10 senders that the owner lists. From an accepted email we keep only the attachment. We discard the sender, the subject and the body. We discard mail from any other sender. We log every delivery, accepted or refused, for 90 days. The log holds the outcome, a reason code, the attachment count and a hash of the message identifier. Mail to a receipt address passes through our email supplier before it reaches us.

4.5Information collected automatically

Session information. A session cookie that keeps you signed in. Your IP address, browser type and operating system reach our server with every request. We do not keep them, except a hashed address after a failed sign-in.

Referral cookie. Tally Tame has a referral programme. Each member has a referral code and a link. If you open a member's link, a cookie named tallytame.ref stores that code for 30 days. We read the cookie once, when you create an account, to credit the referral. Scripts cannot read it. It does not track you. If you arrive any other way, it is never set. You can also enter a member's code yourself, in Settings, Plan, within 14 days of creating your account. That path sets no cookie.

The referrer sees 2 counts: friends who joined, and rewards earned. The referrer never sees your name, your email address, your plan or a payment. You see only the code you used. Nobody outside Tally Tame receives anything about a referral. Section 16.4 describes the reward.

Text-message delivery records. For every text we send, we keep the date and the delivery outcome. We keep your number with all but the last 4 digits masked. We keep no message content. Our text-message supplier reports the delivery outcome to us.

Server logs. The app keeps no request log. The server keeps at most 30 MB of error output per app and overwrites it as it fills, in practice within days. A failed sign-in is recorded as a hashed address for 90 days.

Activity log. Each workspace records every change with who made it and when. It never records an amount. Entries expire after 1 year by default.

Push subscription. If you turn on push notifications, your browser gives us a subscription address and encryption keys. We store them so that we can send you messages. We encrypt every message before it leaves our server, by the web push standard (RFC 8291). The push service of your browser maker carries the message but cannot read it.

Device storage. The installed app caches only its offline page. It stores your sign-in session and your display preferences. No financial record is stored on your device. Sign-out clears the app's local preferences, except the theme.

Measurement. The site and the app measure use with Umami, an open-source analytics engine that we run ourselves on our own server in Toronto. It has no public address. Your browser sends each measurement only to our app. Our app checks it and passes it to the engine over an internal network. No script from another company loads. No measurement goes to another company. No supplier is involved, beyond the encrypted backups in section 10.

For each page view or event we record:

  • The screen name, with every identifier removed before it leaves your browser. We record "accounts.detail", never the address of a specific account. Our server refuses anything that still carries an identifier.
  • The referring site (domain only), the campaign tags on a link to the marketing site, and your browser, operating system, device type, screen size and language.
  • Your country, region and city, derived on our server from your IP address with a local database. The IP address itself is not stored.
  • A visitor number: a hash of your IP address and browser under a secret salt that changes every month. The same person is a different number next month. The number is never linked to an account.
  • Named events from a fixed list: sign-up completed, address verified, two-step enrolled, workspace created, first account added, first expense added, bank connected, receipt uploaded, trial started, subscription started, subscription ended, referral qualified, and a click on the sign-up button on the marketing site. An event can carry only a category value, such as the workspace type or the plan name. An amount cannot be recorded. The list is enforced in code and by tests.

Measurement sets no cookie. It records no user identifier, no email address, no page address with an identifier in it, no page content, no amount, no balance, no financial record and no precise location.

If your browser sends the "Do Not Track" or the Global Privacy Control signal, you are not measured at all. Our server discards the measurement before reading it.

Staff see the result in the staff portal, as counts and charts only. The same screen shows counts from our own database: active accounts per day, how many people from a sign-up week came back, use per module, and trials that converted. Every figure is a count. No staff screen shows an individual visitor.

We do not run advertising trackers. We do not load scripts from other companies. We do not collect precise location.

4.6Payment information

Stripe, Inc. handles payment. When you buy Premium, you enter your card on a page that Stripe hosts. We never receive your full card number. From Stripe we store a customer identifier and your plan: its status, billing interval, price, currency, period and trial dates. We also store the identifiers of your invoices, with links to Stripe's hosted invoice and PDF. We do not store the card brand, the last 4 digits, the expiry or a billing address. Stripe holds them. Stripe's privacy policy is at https://stripe.com/privacy.

4.7Sample data and templates

Sample data is a made-up household. It contains no real person. Workspace templates shape an empty workspace with categories and a budget structure. They never contain an invented amount.

5

Why we use your information

We use personal information only for the purposes in this table. In Canada the basis for every purpose is your consent. You give it when you create an account, connect a bank, upload a receipt or turn on a feature. You can withdraw consent at any time (section 15). The last column names the legal basis in the words that some other countries' laws use.

  • Purpose
    Provide the app: store your records, calculate balances, budgets, interest, payoff plans, forecasts and reports
    Information used
    Account, workspace and financial records
    Legal basis
    Contract
  • Purpose
    Sync bank transactions and put them in your inbox to confirm
    Information used
    Plaid data, your rules
    Legal basis
    Contract, with your separate consent to connect
  • Purpose
    Read receipts and statements with an AI model and prefill fields for you to confirm
    Information used
    Receipt and statement images
    Legal basis
    Consent, given when you use the feature
  • Purpose
    Keep the lines of a receipt and match each one to an item in your workspace, so you can see how often and at what cost you buy it
    Information used
    Receipt lines, the items in your workspace
    Legal basis
    Contract. "Keep these items" is a switch on the review dialog.
  • Purpose
    Send a 6-digit sign-in code by text message, if you chose text-message verification
    Information used
    Mobile phone number
    Legal basis
    Consent, given with a separate checkbox before the first text. Withdraw it by replying STOP or by removing the number.
  • Purpose
    Suggest a category and a tag for an imported row
    Information used
    Your rules, your history for that merchant, a built-in keyword table
    Legal basis
    Contract
  • Purpose
    Detect subscriptions, recurring expenses and unusual expenses in your own records
    Information used
    Your expenses and transactions
    Legal basis
    Contract
  • Purpose
    Let members of a workspace work together under the roles and permissions the owner set
    Information used
    Member details, financial records
    Legal basis
    Contract
  • Purpose
    Show market prices and exchange rates as estimates
    Information used
    Ticker symbols and currencies only
    Legal basis
    Contract
  • Purpose
    Send notifications you turned on, a daily digest, planning alerts and reminders
    Information used
    Contact details, preferences, calendar entries
    Legal basis
    Contract, and consent for push
  • Purpose
    Credit a referral and grant the reward to both sides
    Information used
    The referral code, the date you created your account, and the date of your first payment
    Legal basis
    Contract. You opt out by not using a code or a link.
  • Purpose
    Measure how the site and the app are used, as counts: which screens are visited, where visitors come from, which steps of sign-up are completed
    Information used
    Measurement records (section 4.5). They are never linked to your account.
    Legal basis
    Legitimate interest in understanding and improving the product. A "Do Not Track" or Global Privacy Control signal opts you out.
  • Purpose
    Send security notices about your account
    Information used
    Contact details, session information
    Legal basis
    Legitimate interest in the security of your account. These notices cannot be silenced.
  • Purpose
    Bill you and issue invoices
    Information used
    Payment information from Stripe
    Legal basis
    Contract, and legal obligation for tax records
  • Purpose
    Keep your account safe: two-step verification, breach checks on passwords, rate limits, lockouts
    Information used
    Account and session information
    Legal basis
    Legitimate interest in security, and legal obligation to protect personal information
  • Purpose
    Find and stop abuse, fraud and attacks on the service
    Information used
    Session information, failed sign-in records, error output
    Legal basis
    Legitimate interest in a working and lawful service
  • Purpose
    Answer support requests
    Information used
    Support messages, account information
    Legal basis
    Contract
  • Purpose
    Send marketing email about Tally Tame. We send none today. If we start, we ask for a separate opt-in first.
    Information used
    Email address, marketing choice
    Legal basis
    Consent. You can withdraw it in 1 click.
  • Purpose
    Obey the law, answer lawful requests, establish or defend legal claims
    Information used
    Any of the above, as required
    Legal basis
    Legal obligation, legitimate interest
Table 1 in section 5
PurposeInformation usedLegal basis
Provide the app: store your records, calculate balances, budgets, interest, payoff plans, forecasts and reportsAccount, workspace and financial recordsContract
Sync bank transactions and put them in your inbox to confirmPlaid data, your rulesContract, with your separate consent to connect
Read receipts and statements with an AI model and prefill fields for you to confirmReceipt and statement imagesConsent, given when you use the feature
Keep the lines of a receipt and match each one to an item in your workspace, so you can see how often and at what cost you buy itReceipt lines, the items in your workspaceContract. "Keep these items" is a switch on the review dialog.
Send a 6-digit sign-in code by text message, if you chose text-message verificationMobile phone numberConsent, given with a separate checkbox before the first text. Withdraw it by replying STOP or by removing the number.
Suggest a category and a tag for an imported rowYour rules, your history for that merchant, a built-in keyword tableContract
Detect subscriptions, recurring expenses and unusual expenses in your own recordsYour expenses and transactionsContract
Let members of a workspace work together under the roles and permissions the owner setMember details, financial recordsContract
Show market prices and exchange rates as estimatesTicker symbols and currencies onlyContract
Send notifications you turned on, a daily digest, planning alerts and remindersContact details, preferences, calendar entriesContract, and consent for push
Credit a referral and grant the reward to both sidesThe referral code, the date you created your account, and the date of your first paymentContract. You opt out by not using a code or a link.
Measure how the site and the app are used, as counts: which screens are visited, where visitors come from, which steps of sign-up are completedMeasurement records (section 4.5). They are never linked to your account.Legitimate interest in understanding and improving the product. A "Do Not Track" or Global Privacy Control signal opts you out.
Send security notices about your accountContact details, session informationLegitimate interest in the security of your account. These notices cannot be silenced.
Bill you and issue invoicesPayment information from StripeContract, and legal obligation for tax records
Keep your account safe: two-step verification, breach checks on passwords, rate limits, lockoutsAccount and session informationLegitimate interest in security, and legal obligation to protect personal information
Find and stop abuse, fraud and attacks on the serviceSession information, failed sign-in records, error outputLegitimate interest in a working and lawful service
Answer support requestsSupport messages, account informationContract
Send marketing email about Tally Tame. We send none today. If we start, we ask for a separate opt-in first.Email address, marketing choiceConsent. You can withdraw it in 1 click.
Obey the law, answer lawful requests, establish or defend legal claimsAny of the above, as requiredLegal obligation, legitimate interest

To have an account you must give an email address and a password. Everything else is optional. Without a bank connection there is no bank sync. Without a receipt there is no scan. Without an email address there is no account.

The app asks for your consent in the moment at 3 points: the first bank connection, the first reading of a receipt or statement, and the first text message. It records each consent with the version of this policy. You can withdraw any of the 3 consents in Settings. Settings, Data and privacy, lists each consent with its date. Sign-up records your acceptance of this policy and of the terms, with the version and the time.

We do not use your personal information to train AI models. We do not build advertising profiles. We do not make decisions about you that have legal effect on you without a human.

We never use financial records for a purpose you did not expect. A "purpose you did not expect" includes selling them, scoring you, ranking you against other people, or sending them to an advertiser.

6

Features that use an AI model

Receipt scanning and statement reading use a vision model. The model runs at a third-party supplier. This section says exactly what happens.

  • What is sent. The receipt image or statement file you chose, downscaled in your browser. With it, a short instruction that asks the model to find the merchant, its address, the amount, the date, the tax total, each tax line printed, and the lines printed.
  • Who receives it. OpenRouter, Inc. (United States), which routes the request to an AI model provider. Today that provider is Google. Every request instructs OpenRouter to use only providers that neither keep nor train on the data.
  • What comes back. Suggested values for you to confirm. For a receipt, the merchant, its address, the amount, the date, the tax total, each tax line the receipt prints, and the lines printed on it (section 4.1). The address proposes the place the purchase was made for tax purposes. The expense keeps only that place, at province or state level, never the address. For a statement, its transactions; every prefilled field carries a confidence, and anything uncertain is badged "Check this". Nothing is written to your books until you confirm it.
  • The consent you give. Before the first read, the app asks for your consent. The consent describes the recipient as a third-party AI service and points to this section. This section is the place that names the supplier and the model provider, and it is versioned, so the name is always current. One consent covers receipts and statements.
  • Training. We do not use your images or text to train a model. Our supplier's setting that blocks providers that train on data is on, and every request requires zero data retention.
  • Your choice. You do not have to scan. You can type a receipt, or import a CSV that never leaves your browser.
  • Limits on the Free plan. 5 scans a month.

A scan is a suggestion. It is not a decision about you. You can change every field before you save it.

7

Automated features that work on your records

Tally Tame runs several automated features on your own records, for you. None of them profiles you for advertising. None of them decides anything that has legal effect on you. Each one produces a suggestion, an estimate or a notice that you can change, dismiss or ignore.

  • Feature
    Rules engine
    What it does
    Categorises, renames and can auto-confirm synced lines by rules you wrote
    Your control
    You write, edit and delete the rules. Each rule is on or off.
  • Feature
    Category suggestions
    What it does
    Proposes a category for an imported row
    Your control
    You confirm each row. Auto-accept is a switch per workspace, off by default.
  • Feature
    Item matching
    What it does
    Matches a line read from a receipt to an item in your workspace by its name. A tie is left unmatched.
    Your control
    You edit or unmatch any line. "Keep these items" is a switch on the review dialog.
  • Feature
    Tax place
    What it does
    Proposes the place a purchase was made from the merchant's address on the receipt, or from the workspace's default place
    Your control
    You choose any place on the expense.
  • Feature
    Receipt reconciliation
    What it does
    When you record a payment from a confirmed receipt and your bank later sends the same purchase within 7 days for the same amount to the cent, keeps 1 record and lets the bank's figure win
    Your control
    When it is not sure, it inserts the bank line, keeps yours, and asks you. Nothing is deleted without you. The notice it sends counts receipts and states no figure.
  • Feature
    Subscription detection
    What it does
    Finds repeating charges in your expenses
    Your control
    You confirm or dismiss each finding. The owner can switch it off in workspace settings.
  • Feature
    Anomaly sweep
    What it does
    Flags an expense that does not match your usual pattern
    Your control
    You dismiss a finding. The owner can switch it off in workspace settings.
  • Feature
    Planning alerts (Premium)
    What it does
    Warns when a budget or a forecast crosses a line you set
    Your control
    You set and remove the lines and the notifications
  • Feature
    Forecast
    What it does
    Walks your cash day by day for 30, 60 or 90 days from what is on file
    Your control
    It is an estimate. It records nothing.
  • Feature
    Interest, minimum payment and payoff
    What it does
    Calculates from the terms you entered, and discloses the method
    Your control
    You edit the terms
  • Feature
    Depreciation and market prices
    What it does
    Shows an estimate that never moves net worth until you record it
    Your control
    You decide what to record
Table 1 in section 7
FeatureWhat it doesYour control
Rules engineCategorises, renames and can auto-confirm synced lines by rules you wroteYou write, edit and delete the rules. Each rule is on or off.
Category suggestionsProposes a category for an imported rowYou confirm each row. Auto-accept is a switch per workspace, off by default.
Item matchingMatches a line read from a receipt to an item in your workspace by its name. A tie is left unmatched.You edit or unmatch any line. "Keep these items" is a switch on the review dialog.
Tax placeProposes the place a purchase was made from the merchant's address on the receipt, or from the workspace's default placeYou choose any place on the expense.
Receipt reconciliationWhen you record a payment from a confirmed receipt and your bank later sends the same purchase within 7 days for the same amount to the cent, keeps 1 record and lets the bank's figure winWhen it is not sure, it inserts the bank line, keeps yours, and asks you. Nothing is deleted without you. The notice it sends counts receipts and states no figure.
Subscription detectionFinds repeating charges in your expensesYou confirm or dismiss each finding. The owner can switch it off in workspace settings.
Anomaly sweepFlags an expense that does not match your usual patternYou dismiss a finding. The owner can switch it off in workspace settings.
Planning alerts (Premium)Warns when a budget or a forecast crosses a line you setYou set and remove the lines and the notifications
ForecastWalks your cash day by day for 30, 60 or 90 days from what is on fileIt is an estimate. It records nothing.
Interest, minimum payment and payoffCalculates from the terms you entered, and discloses the methodYou edit the terms
Depreciation and market pricesShows an estimate that never moves net worth until you record itYou decide what to record

Quebec law asks us to tell you about technology that can identify, locate or profile you. Tally Tame does not collect your precise location. Measurement (section 4.5) derives a country, region and city from your IP address, never links it to your account, and stops if your browser sends "Do Not Track". Tally Tame does not identify you across other sites or apps. The features above analyse only the records inside your own workspace, for you. The table says where each switch is. Forecast, interest, depreciation and market prices have no switch because they record nothing.

8

Bank connections through Plaid

Bank sync is a Premium feature. It uses Plaid Inc. ("Plaid"). This is how it works and what it means for your information.

  1. You choose your bank inside Plaid's hosted flow, on Plaid's screens.
  2. You sign in to your bank on those screens. Your bank password goes to Plaid and to your bank. It never reaches Tally Tame.
  3. Plaid gives us a read-only access token for the accounts you chose.
  4. We ask Plaid for new transactions when Plaid tells us that new lines exist. A sync is not instant.
  5. New lines land in your inbox to confirm as expenses.

When you connect a bank you give Plaid and Tally Tame the right to access and transmit your information from your bank, on your behalf. Plaid's own privacy policy governs what Plaid does with that information. Read it at https://plaid.com/legal/#end-user-privacy-policy. Plaid stores data in the United States.

You can disconnect a bank at any time in the app. That revokes our token at Plaid at once. Transactions already in your books stay until you delete them. To see and remove the connections Plaid holds for you, use the Plaid Portal at https://my.plaid.com. To see or delete what Plaid holds, use Plaid's data request form at https://my.plaid.com/data-subject-request-form or write to privacy@plaid.com. Both serve people in Canada and in the United States.

Bank sync is available for banks in Canada and in the United States. The country you gave at sign-up decides which country's banks you are offered. You cannot connect a bank in the other country. You can correct your country in Settings. A correction re-checks whether you may use Tally Tame (terms of service, section 3). A bank already connected stays connected when you correct your country.

9

Who can see your information

9.1Members of your workspace

Members see what the owner allows. The owner sets a role (owner, editor, viewer) and per-member module permissions: accounts, debts, expenses, budgets, goals, assets, reports. Export is a separate permission. An editor can change or delete records, including records about you. If you leave a workspace, the records you entered stay in the workspace. The activity log shows who changed what.

Think before you invite. A member you add can see everything that their permissions allow.

9.2People you authorise

You can create a personal access token and give it to software you trust. The token is read-only and is scoped to the modules you choose. The software then sees the same rows that the CSV export defines. You can revoke a token at any time. A token dies with your membership.

9.3Our suppliers

The companies below process personal information for us, on our instructions, and only for the purpose stated. A data processing agreement is in force with every supplier: 6 by incorporation into their terms, and Plaid under its master agreement. We do not permit them to use your information for their own purposes. None of them receives your full financial records except where the table says so.

  • Supplier
    DigitalOcean, LLC
    Purpose
    Hosting of the app server and the database
    Location of processing
    Toronto, Canada. The company is in the United States.
    What it receives
    All data in the app, encrypted at rest
  • Supplier
    Cloudflare, Inc.
    Purpose
    File storage and our daily backup copy
    Location of processing
    Eastern North America, every bucket
    What it receives
    Receipts, statements, photos, profile pictures and workspace photos (private bucket); organization logos (public bucket); an encrypted daily copy of the database and of the private bucket (backup bucket, kept 30 days)
  • Supplier
    Plaid Inc.
    Purpose
    Bank connections (Premium)
    Location of processing
    United States
    What it receives
    Bank account and transaction data for the accounts you connect. Privacy policy: https://plaid.com/legal/#end-user-privacy-policy
  • Supplier
    Stripe, Inc.
    Purpose
    Billing
    Location of processing
    United States and worldwide
    What it receives
    Email, card details you enter on Stripe's page, plan and invoices. Privacy policy: https://stripe.com/privacy
  • Supplier
    OpenRouter, Inc. and the AI model provider it routes to
    Purpose
    Reading of receipts and statements. Also reading of published government sales tax rate pages, which contain no personal information.
    Location of processing
    United States
    What it receives
    The image or file you chose to scan, with no other record
  • Supplier
    Resend, Inc.
    Purpose
    Sending email, and receiving mail sent to a receipt address
    Location of processing
    United States
    What it receives
    Your email address, the subject and body of each email we send, and receipt email before we file the attachment
  • Supplier
    Telnyx LLC
    Purpose
    Sending sign-in codes by text message, if you chose text-message verification
    Location of processing
    United States (Chicago)
    What it receives
    Your mobile phone number and the text of the code. It reports back whether the text was delivered.
  • Supplier
    GitHub, Inc.
    Purpose
    Build and storage of our software images
    Location of processing
    United States
    What it receives
    No personal information
  • Supplier
    Finnhub
    Purpose
    Market prices
    Location of processing
    United States
    What it receives
    Ticker symbols only. No personal information.
  • Supplier
    Bank of Canada Valet
    Purpose
    Exchange rates
    Location of processing
    Canada
    What it receives
    Currency codes only. No personal information.
  • Supplier
    Browser push services (Google, Apple, Mozilla)
    Purpose
    Delivery of push notifications
    Location of processing
    Worldwide
    What it receives
    An encrypted message they cannot read, and your subscription address
Table 1 in section 9.3
SupplierPurposeLocation of processingWhat it receives
DigitalOcean, LLCHosting of the app server and the databaseToronto, Canada. The company is in the United States.All data in the app, encrypted at rest
Cloudflare, Inc.File storage and our daily backup copyEastern North America, every bucketReceipts, statements, photos, profile pictures and workspace photos (private bucket); organization logos (public bucket); an encrypted daily copy of the database and of the private bucket (backup bucket, kept 30 days)
Plaid Inc.Bank connections (Premium)United StatesBank account and transaction data for the accounts you connect. Privacy policy: https://plaid.com/legal/#end-user-privacy-policy
Stripe, Inc.BillingUnited States and worldwideEmail, card details you enter on Stripe's page, plan and invoices. Privacy policy: https://stripe.com/privacy
OpenRouter, Inc. and the AI model provider it routes toReading of receipts and statements. Also reading of published government sales tax rate pages, which contain no personal information.United StatesThe image or file you chose to scan, with no other record
Resend, Inc.Sending email, and receiving mail sent to a receipt addressUnited StatesYour email address, the subject and body of each email we send, and receipt email before we file the attachment
Telnyx LLCSending sign-in codes by text message, if you chose text-message verificationUnited States (Chicago)Your mobile phone number and the text of the code. It reports back whether the text was delivered.
GitHub, Inc.Build and storage of our software imagesUnited StatesNo personal information
FinnhubMarket pricesUnited StatesTicker symbols only. No personal information.
Bank of Canada ValetExchange ratesCanadaCurrency codes only. No personal information.
Browser push services (Google, Apple, Mozilla)Delivery of push notificationsWorldwideAn encrypted message they cannot read, and your subscription address

We do not use Flinks or any other bank data provider.

9.4Our staff

Tally Tame has a staff portal. Access requires two-step verification. Every change a staff member makes is audited. Staff look at your records only to answer a request you made, to fix a fault, or to investigate abuse. Every lookup of an account by staff is logged. Today 1 person has that access.

For customer support, a staff member with the organisation-manager role or higher can look up an account by email address or name. The lookup shows: your name, your email address and whether it is verified; when the account was created; your locale and time zone; your country and region; the versions of the terms and of this policy you accepted and when; whether two-step verification is on and since when; whether the account is locked after failed sign-ins; the number of active sessions and the country and city of the newest one; your plan and subscription status; the workspaces you belong to, with your role and the member count; the consents you gave or withdrew; your referral code and counts; and your notification channel preferences.

The lookup never shows a balance, a transaction, an expense, a receipt or an amount. It never shows a password, a two-step secret, a recovery code or a session token.

Every lookup is written to the staff audit log: who looked, at whom, and when. Staff can also end your sessions, clear a sign-in lockout, and write a support note. Each of those actions is logged. Resetting two-step verification and closing an account are not portal actions. A staff member runs them by command on the server, after confirming your identity through a second channel.

9.5When the law requires it

We disclose personal information when a law, a court order or a lawful request from a public authority requires it. We check every request. We tell you about it when the law allows us to.

9.6If the business changes hands

If Pixibiz sells Tally Tame, merges, or becomes insolvent, your information can pass to the new operator. We tell you by email before that happens, at least 30 days ahead where the law allows it. The new operator must honour this policy or give you a way to delete your account first.

9.7What we never do

We never sell personal information. We never rent it. We never share financial records with an advertiser, a data broker, a credit bureau, a lender or an insurer. We never receive a fee or a benefit for your information. No such arrangement exists. Mobile phone numbers and text-message consent are used only to send sign-in verification codes. They are not sold, and they are not shared with third parties or affiliates for marketing purposes. We never use the lines of your receipts to compare prices between people.

10

Where your information is stored

Canada. The app server and the database are in Toronto, Ontario. Files you upload (receipts, statements, photos, logos and profile pictures) are stored with Cloudflare in eastern North America. The database is a managed cluster, encrypted at rest, reachable only from the app server over an encrypted connection. Backups are encrypted. Every day we also take an encrypted copy of the database and of your files to a separate Cloudflare storage location in eastern North America. We keep each daily copy for 30 days. Measurement records (section 4.5) are in a database of their own on the same cluster in Toronto, and the backups above cover them.

Outside Canada. The suppliers in section 9.3 process some information in the United States. When personal information is in another country, the courts, police and security agencies of that country can require access to it under their own laws. We remain responsible for your information while a supplier holds it.

If you live outside Canada. Your records are stored in Canada all the same. Canadian law governs how we hold them there, and the authorities of Canada can require access to them under Canadian law.

Suppliers' own transfer safeguards. Some suppliers hold a certification under the EU-US Data Privacy Framework, or sign standard contractual clauses. Where they do, we rely on it in addition to Canadian law. Write to us for a copy of a supplier's clauses.

11

How long we keep your information

We keep personal information only as long as this table says. After that we delete it or make it anonymous.

  • Information
    Account, workspaces and financial records
    How long
    While your account exists, then 30 days after you delete the account. During the 30 days you can undo the deletion. After that we erase everything, files included.
  • Information
    A deleted workspace
    How long
    7 days, then erased
  • Information
    A deleted account (single account inside a workspace)
    How long
    Removed at once. Expenses linked to it are kept.
  • Information
    Receipts, statements and photos
    How long
    Same as the record they belong to
  • Information
    Receipt lines and the items they build
    How long
    Same as the workspace they belong to
  • Information
    The tax parts of an expense, and the workspace's tax settings
    How long
    Same as the workspace they belong to
  • Information
    Mobile phone number, text-message consent and opt-out
    How long
    While your account exists, then erased with it
  • Information
    Text-message delivery records (date, outcome, masked number)
    How long
    While your account exists, then erased with it
  • Information
    Activity log entries
    How long
    1 year by default, then expired
  • Information
    Financial history on the Free plan
    How long
    Records older than 12 months are kept, not deleted. The Free plan does not show them. Premium shows them again.
  • Information
    Sample data
    How long
    Until you remove it, in 1 action
  • Information
    Sessions
    How long
    Until expiry, 30 days from your last use
  • Information
    Failed sign-in attempts (hashed address)
    How long
    90 days
  • Information
    Server error output
    How long
    Overwritten as it fills, in practice within days. There is no request log.
  • Information
    Scheduled job ledger
    How long
    1 year. It holds no financial record.
  • Information
    Scan usage ledger (a count per scan, no image)
    How long
    1 year
  • Information
    Provider webhook events (Stripe, Plaid)
    How long
    90 days
  • Information
    Receipt email delivery log
    How long
    90 days
  • Information
    Push subscriptions
    How long
    Until you turn push off, or the browser cancels the subscription
  • Information
    Personal access tokens
    How long
    Until you revoke them, or your membership ends
  • Information
    Referral code, referral counts and rewards
    How long
    While your account exists
  • Information
    Measurement records (section 4.5)
    How long
    For as long as we run the service, then deleted. They cannot identify you, and the purpose, measuring the product over time, does not end.
  • Information
    Support notes written by staff about your account (section 9.4)
    How long
    While your account exists, then erased with it
  • Information
    Staff audit log: who looked at or acted on an account, and when (section 9.4)
    How long
    For as long as we run the service. It is the record of what staff did. It holds no financial record.
  • Information
    Support email
    How long
    3 years after the last message in the thread
  • Information
    Billing records at Stripe and our copies
    How long
    6 years after the end of the tax year, as Canadian tax law requires
  • Information
    Email logs at our email supplier
    How long
    30 days at Resend
  • Information
    Records of a privacy breach
    How long
    5 years. Canadian federal law requires 24 months and Quebec law requires 5 years.
  • Information
    Backups
    How long
    The hosting supplier keeps 7 days of database backups. Our own daily copy of the database and files is kept for 30 days. A deleted record can persist in a backup for up to 30 days.
Table 1 in section 11
InformationHow long
Account, workspaces and financial recordsWhile your account exists, then 30 days after you delete the account. During the 30 days you can undo the deletion. After that we erase everything, files included.
A deleted workspace7 days, then erased
A deleted account (single account inside a workspace)Removed at once. Expenses linked to it are kept.
Receipts, statements and photosSame as the record they belong to
Receipt lines and the items they buildSame as the workspace they belong to
The tax parts of an expense, and the workspace's tax settingsSame as the workspace they belong to
Mobile phone number, text-message consent and opt-outWhile your account exists, then erased with it
Text-message delivery records (date, outcome, masked number)While your account exists, then erased with it
Activity log entries1 year by default, then expired
Financial history on the Free planRecords older than 12 months are kept, not deleted. The Free plan does not show them. Premium shows them again.
Sample dataUntil you remove it, in 1 action
SessionsUntil expiry, 30 days from your last use
Failed sign-in attempts (hashed address)90 days
Server error outputOverwritten as it fills, in practice within days. There is no request log.
Scheduled job ledger1 year. It holds no financial record.
Scan usage ledger (a count per scan, no image)1 year
Provider webhook events (Stripe, Plaid)90 days
Receipt email delivery log90 days
Push subscriptionsUntil you turn push off, or the browser cancels the subscription
Personal access tokensUntil you revoke them, or your membership ends
Referral code, referral counts and rewardsWhile your account exists
Measurement records (section 4.5)For as long as we run the service, then deleted. They cannot identify you, and the purpose, measuring the product over time, does not end.
Support notes written by staff about your account (section 9.4)While your account exists, then erased with it
Staff audit log: who looked at or acted on an account, and when (section 9.4)For as long as we run the service. It is the record of what staff did. It holds no financial record.
Support email3 years after the last message in the thread
Billing records at Stripe and our copies6 years after the end of the tax year, as Canadian tax law requires
Email logs at our email supplier30 days at Resend
Records of a privacy breach5 years. Canadian federal law requires 24 months and Quebec law requires 5 years.
BackupsThe hosting supplier keeps 7 days of database backups. Our own daily copy of the database and files is kept for 30 days. A deleted record can persist in a backup for up to 30 days.

If a law requires us to keep a record longer, or a legal claim is open, we keep only what that requires.

12

How we protect your information

These are the measures we run today.

  • We require two-step verification for every account, by authenticator app or by text message. You enrol during sign-up. We issue recovery codes. The authenticator app is the safer choice: a text message can be moved to another phone by somebody who tricks a mobile operator.
  • A text-message code is 6 digits, expires after 3 minutes and allows 5 attempts. Codes are stored hashed. Changing the number takes your password and a live code, and is confirmed by a code sent to the new number.
  • Every connection uses TLS 1.2 or 1.3 with HSTS.
  • The database is encrypted at rest with keys that the hosting supplier holds. Backups are encrypted.
  • The server checks your access on every request. A test enumerates every endpoint against another workspace's identifiers.
  • We check passwords against known breach lists. We rate limit sign-in and lock it per account. The lockout never reveals whether an address exists.
  • We identify uploaded files by their bytes, strip their metadata, and serve them only through a membership check.
  • No amount from your records ever appears in an email, a notification, a push message or a text message. The build enforces this.
  • No advertising tracker and no script from another company runs in the app. The only measurement is the first-party, cookieless measurement in section 4.5, which runs on our own server and never leaves it.
  • Staff access uses a separate portal with mandatory two-step verification and an audit of every change and of every lookup of an account.

No system is perfectly secure. We do not promise that a breach cannot happen. We promise what section 13 says.

13

If a breach happens

If we learn that personal information was lost, stolen or accessed without permission, we act at once.

  1. We contain the breach and record it in our breach register.
  2. If the breach creates a real risk of significant harm to you, we notify you as soon as feasible. In Quebec the test is a risk of serious injury. We use email and an in-app notice. We tell you what happened, what information was involved, what we did, and what you can do.
  3. We report the breach to the Office of the Privacy Commissioner of Canada. We also report it to any other regulator the law names.
  4. We notify a bank, Plaid or another organization when that helps reduce the harm.
14

Your choices and controls

You control most of this without writing to us.

  • To
    See everything you own
    Do this
    Export a CSV, a workspace ZIP with a manifest, or an archive of your whole account. No request to staff, no waiting.
  • To
    Delete your account
    Do this
    Choose delete in settings. You have 30 days to change your mind. Then we erase everything.
  • To
    Delete a workspace
    Do this
    Choose delete. You have 7 days to change your mind.
  • To
    Disconnect a bank
    Do this
    Remove the connection in the app. The token is revoked at once.
  • To
    Stop a scan feature
    Do this
    Do not use it. Type the receipt or import a file instead.
  • To
    Change notifications
    Do this
    Set preferences per category, per workspace and for the daily digest. Security notices stay on.
  • To
    Turn off push
    Do this
    Turn it off in the app or in your browser settings.
  • To
    Stop text messages
    Do this
    Reply STOP to any text, or remove your number in Settings. Sign in with your authenticator app or your recovery codes instead. Two-step verification stays on.
  • To
    Stop keeping receipt lines
    Do this
    Switch off "Keep these items" on the review dialog. Delete any line or item in the workspace.
  • To
    Stop marketing email
    Do this
    We send none today. If we start, every marketing email has an unsubscribe link, and we act within 10 business days. Service and security email continues, because it is part of the service.
  • To
    Revoke a personal access token
    Do this
    Delete it in settings.
  • To
    Remove a member
    Do this
    The owner removes the member. Their access ends at once.
  • To
    Leave a workspace
    Do this
    Leave from the workspace settings.
  • To
    Clear the app from your device
    Do this
    Sign out. That clears the app's local preferences, except the theme. No financial record is on your device. Remove the installed app yourself if you want it gone.
  • To
    Refuse cookies
    Do this
    The app uses 2 cookies (section 18). Block the session cookie and you cannot sign in. Block the referral cookie and everything works, but a referral is not credited.
Table 1 in section 14
ToDo this
See everything you ownExport a CSV, a workspace ZIP with a manifest, or an archive of your whole account. No request to staff, no waiting.
Delete your accountChoose delete in settings. You have 30 days to change your mind. Then we erase everything.
Delete a workspaceChoose delete. You have 7 days to change your mind.
Disconnect a bankRemove the connection in the app. The token is revoked at once.
Stop a scan featureDo not use it. Type the receipt or import a file instead.
Change notificationsSet preferences per category, per workspace and for the daily digest. Security notices stay on.
Turn off pushTurn it off in the app or in your browser settings.
Stop text messagesReply STOP to any text, or remove your number in Settings. Sign in with your authenticator app or your recovery codes instead. Two-step verification stays on.
Stop keeping receipt linesSwitch off "Keep these items" on the review dialog. Delete any line or item in the workspace.
Stop marketing emailWe send none today. If we start, every marketing email has an unsubscribe link, and we act within 10 business days. Service and security email continues, because it is part of the service.
Revoke a personal access tokenDelete it in settings.
Remove a memberThe owner removes the member. Their access ends at once.
Leave a workspaceLeave from the workspace settings.
Clear the app from your deviceSign out. That clears the app's local preferences, except the theme. No financial record is on your device. Remove the installed app yourself if you want it gone.
Refuse cookiesThe app uses 2 cookies (section 18). Block the session cookie and you cannot sign in. Block the referral cookie and everything works, but a referral is not credited.
15

Your rights

Wherever you live, you have these rights over your personal information. Some laws name them differently. We honour them for everyone.

  • Access. Ask what personal information we hold about you and get a copy. The export in the app gives you your records at once. Write to us for anything else.
  • Correction. Fix any inaccurate or incomplete information. You can edit your records in the app. Write to us for anything else.
  • Deletion. Delete your account in the app, or ask us to delete your information. We keep only what a law requires us to keep, and we tell you what that is.
  • Portability. Receive your records in a structured, commonly used, machine-readable format. The CSV and ZIP exports do this. You can also ask us to send them to another organization where that is technically possible.
  • Withdraw consent. Withdraw a consent you gave, at any time. Withdrawal does not undo what happened before it. Some features stop when you withdraw the consent they need.
  • Object and restrict. Object to a use that rests on our legitimate interest, or ask us to restrict a use while we check a dispute.
  • No automated decisions. We make no decision about you by automated means alone that has a legal or similar effect on you. If that ever changes, we tell you first and you can ask for a human review.
  • Complain. Complain to us first. If you are not satisfied, complain to a regulator (section 16).
  • No penalty. We never treat you worse because you exercised a right.

How to exercise a right. Write to the privacy email. Tell us what you want. We may ask you to confirm your identity from the email address on your account. We answer within 30 days. If we refuse a request in whole or in part, we tell you why and how to complain. We do not charge a fee unless a request is repetitive or excessive, and then we tell you the fee first.

Someone acting for you. An authorised agent can make a request for you. We ask for proof of the authorisation and we confirm with you.

16

Information for specific places

16.1Canada

The Personal Information Protection and Electronic Documents Act (PIPEDA) governs how we handle personal information. Where a province has its own private-sector privacy law, that law also applies to residents of that province.

You can complain to the Office of the Privacy Commissioner of Canada: https://www.priv.gc.ca, 1-800-282-1376.

16.2Quebec

Tally Tame is not offered to residents of Quebec today. The app, this policy and the terms of service exist only in English, and Quebec law requires French. Sign-up asks where you live and refuses Quebec. If we learn that an account belongs to a resident of Quebec, we tell the person. We give them 30 days to export their records, and then we close the account.

If you are a resident of Quebec and you hold an account despite that rule, Quebec law still protects you, and we apply it:

  • The person in charge of the protection of personal information at Pixibiz is Johan Teran, Founder. Reach that person at the privacy email in section 2.
  • We ask for your consent separately, in clear words, before we collect sensitive information such as a bank connection or a receipt. The request is not hidden in the terms of service.
  • Your information is stored outside Quebec (section 10).
  • The app's default settings give the highest level of confidentiality. Nobody sees a workspace until you invite them. Push is off until you turn it on. We send no marketing email.
  • Section 7 describes technology that could be seen as profiling. Tally Tame does not collect your precise location and does not identify you across other services.
  • We make no decision about you by exclusively automated means.
  • You have a right to portability, to ask us to stop disseminating information, and to ask for de-indexing.
  • You can complain to the Commission d'accès à l'information du Québec: https://www.cai.gouv.qc.ca.

We plan to offer Tally Tame in Quebec once a French version of the app and of these documents exists. This section changes at that time.

16.3European Economic Area, United Kingdom and Switzerland

Tally Tame is not offered to residents of the European Economic Area, the United Kingdom or Switzerland today. We have no representative there, and the law of those places requires one. Sign-up asks where you live and refuses those places. If we learn that an account belongs to a resident of one of them, we tell the person. We give them 30 days to export their records, and then we close the account.

If you hold an account despite that rule, you keep every right in section 15. You can also complain to the supervisory authority of your country of residence. In the UK that is the Information Commissioner's Office, https://ico.org.uk.

We do not collect special categories of personal information. A transaction description can reveal a sensitive fact about you, for example a payment to a clinic. We do not analyse, categorise or infer any such fact. We treat every transaction the same way.

16.4United States

This section is for residents of California and of other states with a consumer privacy law. We describe our practices in the terms those laws use.

Categories of personal information collected in the last 12 months, and the source.

  • Category
    Identifiers
    Examples
    Email address, mobile phone number if you chose text-message verification, IP address, customer identifier at Stripe
    Source
    You, your browser, Stripe
  • Category
    Customer records
    Examples
    First name, last name
    Source
    You
  • Category
    Financial information
    Examples
    Accounts, balances, transactions, expenses, debts, budgets, goals, assets, receipt lines and items, sales tax parts
    Source
    You, other members, your bank through Plaid
  • Category
    Commercial information
    Examples
    Plan, invoices, payment history
    Source
    Stripe
  • Category
    Internet or network activity
    Examples
    Session information, failed sign-in records, measurement records (section 4.5)
    Source
    Your browser
  • Category
    Geolocation data
    Examples
    Country, region and city derived from an IP address for measurement, never linked to an account. No precise location.
    Source
    Your browser
  • Category
    Visual information
    Examples
    Receipt images, statement images, asset photos, an avatar
    Source
    You
  • Category
    Inferences
    Examples
    A suggested category or tag for a transaction, a detected subscription
    Source
    Derived from your own records
  • Category
    Sensitive personal information
    Examples
    Account sign-in credentials (as a hash), financial account information from Plaid
    Source
    You, Plaid
Table 1 in section 16.4
CategoryExamplesSource
IdentifiersEmail address, mobile phone number if you chose text-message verification, IP address, customer identifier at StripeYou, your browser, Stripe
Customer recordsFirst name, last nameYou
Financial informationAccounts, balances, transactions, expenses, debts, budgets, goals, assets, receipt lines and items, sales tax partsYou, other members, your bank through Plaid
Commercial informationPlan, invoices, payment historyStripe
Internet or network activitySession information, failed sign-in records, measurement records (section 4.5)Your browser
Geolocation dataCountry, region and city derived from an IP address for measurement, never linked to an account. No precise location.Your browser
Visual informationReceipt images, statement images, asset photos, an avatarYou
InferencesA suggested category or tag for a transaction, a detected subscriptionDerived from your own records
Sensitive personal informationAccount sign-in credentials (as a hash), financial account information from PlaidYou, Plaid

Purposes. Section 5. Disclosure to service providers. Section 9.3. Each supplier receives only the categories the table shows.

Sale and sharing. We do not sell personal information. We do not share it for cross-context behavioural advertising. We have not done either in the last 12 months. We have no plan to. We do not sell or share the personal information of anyone under 16, because nobody under 18 may use Tally Tame.

Sensitive personal information. We use it only to provide the service you asked for, to keep your account secure, and as the law permits. We do not use it to infer characteristics about you.

Opt-out preference signals. The app has no advertising and no sale or share to opt out of. We treat a Global Privacy Control signal as a valid request anyway. A browser that sends it receives an acknowledging header on every app page, and it is not measured at all (section 4.5).

Bank connections. If you connect a United States bank, Plaid handles your bank data in the United States under its end user privacy policy. You can see and remove the connections Plaid holds for you at https://my.plaid.com, and ask Plaid about its data through the form in section 8. We receive the same fields for a United States bank as for a Canadian bank (section 4.2).

Retention. Section 11 states how long we keep each category.

Notice of financial incentive. The referral programme is a financial incentive under California law, because it rewards an attributed sign-up. These are its terms.

  • What you give. When you use a member's link or code, we record the code and the date you created your account. Later we record the date of your first Premium payment. Nothing else. The referrer sees only a count.
  • What each side gets. The same number of days of Premium, 30 by default, for you and for the referrer. The reward is earned when you first pay for Premium, or at sign-up if we say so at the time. It is never money. A member who already pays for Premium receives the days as a credit against the next invoice.
  • How to opt in. Open a member's link before you sign up. Or enter their code in Settings, Plan, within 14 days of creating your account.
  • How to opt out. Do not use a link or a code. You can also ask us to remove a referral attribution at any time by writing to the privacy email. Removal ends any reward not yet used.
  • The value of your information. We do not price personal information. We value the incentive at the cost of the days of Premium we give, 30 days at the Premium monthly price. That is the whole value we assign, and the method is the price list in the terms of service.
  • If the programme ends. We can pause or end the programme. A reward already earned stays.

Your rights. Know, access, correct, delete, receive a portable copy, opt out of sale or sharing, limit use of sensitive personal information, and not be discriminated against. Section 15 says how to exercise them. We answer within 30 days, inside the 45 days that state law allows. If we refuse, you can appeal by replying to our answer. We answer the appeal within 30 days. If you still disagree, we tell you how to contact your state attorney general.

California "Shine the Light". We do not disclose personal information to third parties for their direct marketing purposes.

Children. We do not knowingly collect personal information from anyone under 13, or from anyone under 18. See section 17.

Washington My Health My Data Act. We do not collect consumer health data. We do not infer health from your transactions.

16.5Other countries

If you live somewhere not named above, the law of your country can give you rights beyond section 15. We honour them where they apply. Write to us.

17

Age

Tally Tame is for adults. You must be 18 or older to create an account. We do not knowingly collect personal information from anyone under 18. If we learn that we hold information about a person under 18, we delete the account and the information. If you believe that a minor has an account, write to the privacy email.

18

Cookies and device storage

Tally Tame uses only what it needs to work.

  • Item
    Session cookie
    Purpose
    Keeps you signed in
    Lasts
    30 days from your last use, or until you sign out
  • Item
    Referral cookie (tallytame.ref)
    Purpose
    Records the referral link you arrived through, so that the referral is credited when you sign up. Set only when you arrive through such a link. Not readable by scripts.
    Lasts
    30 days
  • Item
    Preference storage
    Purpose
    Remembers your theme and layout
    Lasts
    Until you clear it or sign out. The theme stays after sign-out.
  • Item
    App files cache
    Purpose
    Lets the installed app open when you are offline
    Lasts
    Until you remove the app or clear site data
  • Item
    Push subscription
    Purpose
    Delivers notifications you turned on
    Lasts
    Until you turn push off
Table 1 in section 18
ItemPurposeLasts
Session cookieKeeps you signed in30 days from your last use, or until you sign out
Referral cookie (tallytame.ref)Records the referral link you arrived through, so that the referral is credited when you sign up. Set only when you arrive through such a link. Not readable by scripts.30 days
Preference storageRemembers your theme and layoutUntil you clear it or sign out. The theme stays after sign-out.
App files cacheLets the installed app open when you are offlineUntil you remove the app or clear site data
Push subscriptionDelivers notifications you turned onUntil you turn push off

There is no advertising cookie, no analytics cookie and no third-party cookie. Measurement (section 4.5) sets no cookie. We honour "Do Not Track": a browser that sends it is not measured. None of the items above follows you to another site or app, so no cookie banner appears.

19

Email, notifications, push and text messages

Service messages. We send email that the service needs: sign-up confirmation, security notices, receipts for payment, invoices, notices about your plan, and notifications you turned on. These messages are part of the service. Security notices cannot be silenced.

Marketing messages. We send no marketing email today. If we start, we send it only to people who opted in. The opt-in is a separate, unticked choice. Every marketing email names Pixibiz Digital Inc., carries our mailing address, and has an unsubscribe link that works for at least 60 days. We honour an unsubscribe within 10 business days. This follows Canada's anti-spam law (CASL).

Push notifications. Push is off until you turn it on. You choose the categories. We send no marketing push. If we start, it requires a separate opt-in.

Text messages. If you chose text-message verification, we send a 6-digit code to your mobile phone number. We send it when you sign in or when you change the number. We send nothing else to it. A code expires after 3 minutes. Before the first text, you agree with a separate, unticked checkbox to this wording: "I agree to receive sign-in verification texts from Tally Tame. Reply STOP to opt out. Reply HELP for help. Standard message and data rates may apply. Message frequency may vary." Reply STOP to any text to end texts to that number. Reply HELP for help. We answer HELP by text message, even after you send STOP, because the mobile carriers require it. Replying STOP withdraws your consent and stops every text to that number. Reply START to receive codes again, if your consent is still on file. A word from a phone never restores a consent you withdrew in the app. You can also remove the number in Settings. After that, sign in with your authenticator app or your recovery codes. Two-step verification stays on. Our text-message supplier is Telnyx LLC (section 9.3). Your mobile carrier's standard message and data rates apply. Mobile phone numbers and text-message consent are used only to send sign-in verification codes. They are not sold, and they are not shared with third parties or affiliates for marketing purposes.

No amounts from your records. No email, notification, push message or text message ever contains an amount from your records. A person who reads your inbox or your lock screen sees that a payment is due. That person does not see how much. Billing email is the one exception: the purchase receipt, the yearly renewal reminder, the promotion-end notice and the price-change notice state the plan's price. We send billing email ourselves. Stripe's own emails are off.

20

Changes to this policy

We change this policy when the product, the law or our suppliers change. For a material change we email every account holder at least 30 calendar days before the change takes effect. We show a notice in the app until that date. At your first sign-in after that date, we ask you to accept the new version. A material change is one that expands what we collect, why we use it, or who receives it. For a change that needs your consent, we ask for it before the change applies to you. Each version carries its effective date and a summary of what changed.

  • Version
    1.0
    Date
    2026-09-05
    Change
    First published version.
  • Version
    1.1
    Date
    2026-09-14
    Change
    Two-step verification by text message: the mobile phone number we collect, the consent, STOP and HELP, delivery records, the supplier Telnyx LLC, and the carrier statement that numbers and consent are never shared for marketing (sections 1, 4.1, 4.5, 5, 9.3, 9.7, 11, 12, 14, 16.4, 19). Receipt lines and items kept inside the workspace (sections 1, 3, 4.1, 5, 6, 7, 9.7, 11, 14, 16.4). The AI reading consent covers statements as well as receipts and points to section 6 for the supplier's name (sections 5, 6). Revised on 2026-09-14, before publication, for the same release: HELP answered by text and START (4.1, 19); the reader also returns the merchant's address and each printed tax line, and the raw answer is kept with the receipt (4.1, 6); sales tax kept as named parts on every workspace, the tax place, and a business workspace's GST/HST and QST registration answers (4.1, 7, 11, 16.4); receipt reconciliation (7); OpenRouter also reads published government rate pages (9.3); the measurement event list completed (4.5). Revised again on 2026-09-14, the day bank sync went live, before any customer account existed: bank sync is live for banks in Canada and the United States, the sign-up country decides the banks offered, a country can be corrected in Settings (8); the account fields from Plaid corrected (no interest rate), the debugging extract disclosed and erased with the transaction, and the same fields in both countries (4.2); records of people outside Canada are stored in Canada (10); the Plaid Portal named (8, 16.4).
Table 1 in section 20
VersionDateChange
1.02026-09-05First published version.
1.12026-09-14Two-step verification by text message: the mobile phone number we collect, the consent, STOP and HELP, delivery records, the supplier Telnyx LLC, and the carrier statement that numbers and consent are never shared for marketing (sections 1, 4.1, 4.5, 5, 9.3, 9.7, 11, 12, 14, 16.4, 19). Receipt lines and items kept inside the workspace (sections 1, 3, 4.1, 5, 6, 7, 9.7, 11, 14, 16.4). The AI reading consent covers statements as well as receipts and points to section 6 for the supplier's name (sections 5, 6). Revised on 2026-09-14, before publication, for the same release: HELP answered by text and START (4.1, 19); the reader also returns the merchant's address and each printed tax line, and the raw answer is kept with the receipt (4.1, 6); sales tax kept as named parts on every workspace, the tax place, and a business workspace's GST/HST and QST registration answers (4.1, 7, 11, 16.4); receipt reconciliation (7); OpenRouter also reads published government rate pages (9.3); the measurement event list completed (4.5). Revised again on 2026-09-14, the day bank sync went live, before any customer account existed: bank sync is live for banks in Canada and the United States, the sign-up country decides the banks offered, a country can be corrected in Settings (8); the account fields from Plaid corrected (no interest rate), the debugging extract disclosed and erased with the transaction, and the same fields in both countries (4.2); records of people outside Canada are stored in Canada (10); the Plaid Portal named (8, 16.4).
Questions about this policy?Contact us
Tally Tame
SecurityPricingPrivacyTermsContact

© Copyright 2026 Tally Tame. All Rights Reserved.