Last updated: August 24, 2026
Privacy policy
This policy explains how Tally processes personal data when you use the mobile app to log movements, organize accounts, store receipts and, if you choose, share accounts, analyze receipts with AI, or turn on local automations such as Google Wallet on Android.
1. Data controller
- Controller: Juan Carlos Rodicio
- Tax ID (NIF/CIF): 28793085Y
- Trade name: Tally
- Address for notices: Calle Arroyo 9 41008 Sevilla
- Contact email: support@rcuadrado.es
- Website: this Tally website.
Given the nature and expected scale of the processing, no Data Protection Officer is appointed unless applicable law makes it mandatory.
2. Data we process
Tally is designed to keep personal-finance functional data locally by default. Only data the user chooses to share or use through a remote function is sent to the cloud. We do not connect to banks. Statement import (CSV, Excel, or Norma 43) is a Tally PRO feature; you choose the file and review the movements before they are saved. In Settings you can import a Tally CSV to merge data; that flow is not statement import and does not include row-by-row review.
| Data | Purpose | Origin and storage |
|---|---|---|
| Email and user identifier | Create an account, sign in, and keep access secure. | Provided by the user or the sign-in provider. Managed through Supabase Auth. |
| Name or profile data available from Apple/Google | Basic account identification and sign-in experience. | Only when the user signs in with those providers and they supply that data. |
| Movements, accounts, categories, goals, and recurring items | Provide the core personal-finance functionality and synchronize accounts the user chooses to share. | Entered by the user and stored locally by default. Shared-account data is encrypted on the device before it is sent to Supabase. |
| Imported bank statements | A Tally PRO feature to review and add history from a CSV, Excel, or Norma 43 file you choose. | The file is selected and parsed locally. For optional AI normalization or categorization, limited batches of text and categories are sent to a secure Supabase function; the full file is not stored. |
| Aliases and shared-account participants | Identify invited people, apply permissions, and show who a shared account is shared with. | The alias is tied to the user identifier. Participants in the same shared space can see their aliases and roles. |
| Receipt or ticket photos | Attach supporting documents to movements and allow later review. | Captured with the camera or selected from the gallery. Stored as local files on the device. |
| Receipt image sent for AI analysis | Extract a proposed amount, date, merchant, concept, and category for the user to review. | Sent only when the user taps the explicit analyze-receipt action. Processed through a Supabase function and Google Gemini. |
| Google Wallet payment notifications on Android | Create local drafts of detected payments for the user to review, edit, save, or discard. | Only if the PRO user turns on Google Wallet automation and grants notification access on Android. Processed locally on the device and not sent to servers or third parties. |
| PRO status | Apply free-tier limits and unlock Tally PRO. | Local copy in the app and an entitlement mirror in Supabase. Purchases are validated through RevenueCat, the App Store, and Google Play. |
| App usage events | Understand which screens and features are used so we can prioritize improvements. | Generated by the app only if Help improve Tally is on. Processed through PostHog Cloud EU. |
| Technical data, errors, and diagnostic traces | Security, error diagnosis, bug fixing, and service operation. | Generated by the app and by technical providers such as Supabase, RevenueCat, Sentry, the App Store, or Google Play, as applicable. |
What we do not do
- We do not connect to your bank accounts.
- Statement import is a Tally PRO feature: it starts from a CSV, Excel, or Norma 43 file you choose and is reviewed before movements are saved. Importing a Tally CSV from Settings merges data and does not include row-by-row review.
- We do not sell personal data.
- We do not use your data for behavioral advertising.
- We do not access contacts or precise location.
- We do not read SMS, emails, banks, Samsung Wallet, or other apps to automate payments.
- We do not upload your receipt images when you share an account. They stay on the device; an image is sent only if you expressly ask to analyze the receipt.
- We do not send PostHog or Sentry amounts, concepts, account names, custom category names, emails, photos, receipts, Google Wallet notifications, local paths, CSVs, tokens, or authentication data.
3. App permissions
Camera
Tally may request camera permission to photograph receipts or tickets and attach them to your movements. The camera is used only when you choose this action.
Gallery or photos
Tally may request access to images to select an existing receipt. The app does not analyze or import your entire gallery.
Internet
Tally needs a connection for sign-in, purchases, purchase restoration, shared-account synchronization, optional statement categorization, and AI receipt analysis when the user requests it.
Notification access on Android
On Android, Tally may request notification access only if the user turns on Google Wallet automation. Before opening system settings, the app shows a prominent notice and asks for an affirmative action.
4. Purposes of processing
- Manage registration, sign-in, and account security.
- Allow use of the personal-finance app mainly from the user's device.
- Allow PRO users to share and synchronize the accounts they choose, with edit or read-only permissions.
- Attach receipts to movements and, if the user requests it, analyze them with AI.
- Create local drafts of Google Wallet payments on Android when the user expressly turns on that automation.
- Manage Tally PRO, restore purchases, and apply usage limits.
- Respond to support, privacy, or data-deletion requests.
- Measure screen and feature use in a limited way when the user keeps Help improve Tally turned on.
- Prevent abuse, technical errors, or unauthorized use of remote functions.
- Detect, diagnose, and fix technical failures, errors, and crashes.
We do not make automated decisions with legal or similarly significant effects on the user.
5. Legal basis
- Performance of the contract: providing the app, user account, purchases, and PRO features, including sharing requested by the user.
- Consent: turning on the cloud, camera use, image selection, AI analysis, notification access for Google Wallet on Android, and product analytics if that option is on.
- Legitimate interest: security, abuse prevention, technical diagnosis, error correction, and service improvement.
- Legal obligation: compliance with applicable tax, consumer, or authority requirements.
6. Providers and recipients
We do not share personal data with third parties to sell it or transfer it for commercial purposes. To provide the service we use technical providers that process data under their own terms and applicable agreements.
| Provider | Service | Related data |
|---|---|---|
| Supabase | Authentication, edge functions, PRO status, and optional synchronization of shared accounts. | User identifier, email, session tokens, subscription status, aliases, members, roles, and encrypted functional content of the chosen accounts. |
| Google LLC | Google Sign-In, Google Play, and Google Gemini for AI analysis. | Sign-in data, Android purchases, and receipts voluntarily sent for AI analysis. |
| Apple Inc. | Sign in with Apple and App Store purchases. | Sign-in data and iOS transactions. |
| RevenueCat, Inc. | Purchase, subscription, restoration, and PRO entitlement management. | User identifier, purchased product, subscription status, and purchase events. |
| PostHog | Product analytics and app usage events. | Pseudonymous identifier and limited events. PostHog Cloud EU is used. |
| Sentry | Error, crash, and technical-trace monitoring for diagnosis. | Pseudonymous identifier, technical device/app information, errors, and safe stack traces without user-entered financial content. |
| Vercel, Inc. | Hosting for this marketing site. | Vercel serves the pages. We do not list hosting logs we have not verified. |
| Vercel, Inc. | Vercel Web Analytics on this marketing site, including this page. | Anonymous page views, per Vercel: a one-day hash of the request, URL, referrer, geolocation, operating system, browser, and device type. We do not send custom events. |
Some providers may be located outside the European Economic Area. In those cases, the appropriate safeguards provided by the GDPR apply.
7. Receipts and AI analysis
AI receipt analysis is optional. The app does not analyze a receipt when you attach, open, edit, or replace it. The image is sent only if the user expressly taps the analyze-receipt action.
When this feature is used, Tally may send the compressed image, language, allowed currencies, available local categories, and basic movement context to a secure Supabase function, which then asks Google Gemini for a proposed reading of the receipt. The result is a proposal for the user to review.
Sharing an account does not upload the receipt image. The app may synchronize the encrypted metadata needed to relate the receipt to its movement, but the image file stays local on the device.
8. Google Wallet on Android
Google Wallet automation on Android is optional and is part of Tally PRO. It is turned on only if the user enables it from Settings > Automation > Google Wallet and grants notification access in Android system settings.
Tally uses this access only to identify Google Wallet payment notifications. When it detects a compatible notification, it extracts the data needed to create a local draft. The user must review the draft and can edit, save, or discard it before it becomes a movement.
Google Wallet drafts are stored locally on the device. They are not uploaded to Supabase, Google Gemini, PostHog, Sentry, Supabase Storage, or other servers or third parties.
9. Cloud and shared accounts
Tally works locally by default. The cloud is optional and can be turned on from Settings or when sharing an account. Turning it on does not automatically upload all of the user's finances: it only prepares to synchronize the accounts the user chooses.
When you share an account, it includes the account, its movements, the needed custom categories, recurring movements, and associated receipt metadata. This functional content is encrypted on the device before it is sent to Supabase. Supabase stores the encrypted content together with the minimum data needed to manage members, roles, invitations, and synchronization.
The key that can read the content is not stored in clear text in Supabase. It is delivered encrypted to each authorized participant. When an invitation is accepted, the app downloads and decrypts the data on the recipient's device.
The owner can grant edit or view-only permission, change the role later, and revoke access. Each participant's alias is visible to active members of the same shared space; internal identifiers are not shown as a public name.
If the user turns off the cloud, Tally pauses remote communication without deleting local data. Changes made locally may remain pending and synchronize when the cloud is turned back on.
10. Data retention
- Local personal-finance data is kept on the device until the user edits it, deletes it, or deletes the app/local data.
- Encrypted shared-account data is kept while the shared space remains active or is needed to provide the requested synchronization.
- Local drafts created from Google Wallet are kept on the device until the user saves, edits, or discards them, or deletes the app's local data.
- Account data is kept while the account remains active.
- Analytics events and technical errors are kept for as long as needed to measure use, prioritize improvements, diagnose failures, and maintain security.
- When you request account deletion, we will delete or anonymize the personal data under our control, except data that must be kept due to a legal obligation.
You can start an account-deletion request from Settings in the app or by writing to support@rcuadrado.es. This request does not automatically cancel active App Store or Google Play subscriptions.
11. Your rights
You can exercise your rights of access, rectification, erasure, objection, restriction of processing, and portability by writing to the contact email indicated in this policy.
- Access: know what personal data we process about you.
- Rectification: correct inaccurate or incomplete data.
- Erasure: request deletion of your personal data.
- Portability: receive data in a structured format when applicable.
If you believe the processing does not comply with the law, you can lodge a complaint with the Spanish Data Protection Agency at www.aepd.es.
12. Children
Tally is not directed at children under 16. If you believe a minor has given us personal data without sufficient authorization, contact us so we can review and delete the relevant information.
13. Cookies and similar technologies
This marketing site, including this page, uses Vercel Web Analytics. According to Vercel, that analytics product does not use cookies. Each visit is identified with a hash of the incoming request, valid for one day, and cannot be tracked across days or other sites. Page-view recording is anonymous and is not tied to an individual, a customer, or an IP address. With each data point, Vercel may store a timestamp, URL, dynamic path, referrer, filtered query parameters, geolocation, operating system and version, browser and version, device type, and script version. We mount the default component here, with no custom events.
The mobile app may use product-analytics and crash-reporting SDKs, which you can control in Settings with Help improve Tally and Send technical errors. That is not the same as this website’s analytics.
14. Security
We apply reasonable measures to protect data, such as encryption in transit via HTTPS/TLS, authenticated encryption on the device for shared functional content, secure authentication, per-member permissions, database access policies, and local storage of receipt images in the application's private space. Even so, no system is completely infallible.
15. Changes to this policy
We may update this policy to reflect legal, technical, or service changes. The last-updated date will appear at the start of the document. If the changes are material, we will try to give notice by reasonable means.
16. Contact
For questions about privacy, rights, or account deletion, write to support@rcuadrado.es.