You want to decide
You prefer a clear action —sharing, analysis, or enabling a setting— before an external service is used.
PRIVACY WITHOUT SHORTCUTS
Privacy in a finance app is not just a label. It matters where data lives, what leaves the device, and which actions activate external services.
Updated August 31, 2026
A USEFUL DEFINITION
A privacy-first app should let you understand its behavior: what it needs to work, what it keeps on the device, which external services it uses, and which actions activate them.
Tally does not make absolute privacy promises. Its model is local-by-default and has no bank connection, but it requires an account and offers optional features that need a network. The difference is making those boundaries visible.
FUNCTIONAL DATA
Tally's normal personal-finance workflow is rooted on the device.
Local by default does not mean every piece of data is permanently isolated from every server. The account, purchases, and features you choose to activate have their own boundaries, described below and in the full policy.
AN IMPORTANT DISTINCTION
Tally requires an account and does not offer guest mode. Supabase Auth manages identity and sessions so the app can grant access, but the account does not make Supabase the source of truth for your personal movements, accounts, categories, receipts, or goals.
You can have an account and still keep functional data on the device. That is why local-by-default does not mean account-free or server-free: it means the cloud does not automatically receive all of your finances just because you create an account.
ACCESS TO FINANCIAL DATA
Tally does not connect bank accounts or request credentials to download movements. You can enter them manually or, with PRO, select a CSV, Excel (.xlsx), or Norma 43 file.
The import is analyzed to prepare a preview; you review and confirm proposals before saving them. If you use optional statement enrichment, limited batches of text and categories are sent to a secure function; the full file is not stored. The CSV Tally exports and re-imports from Settings is a merge of your own data and is a different flow.
| Action | What happens | When it activates |
|---|---|---|
| Manual entry | A movement is created from the data you enter in the app. | When you tap save. |
| Statement import | A file is selected and a reviewable preview is prepared. | When you choose import and confirm the PRO flow. |
| Bank connection | This is not a Tally feature. | Never. |
WHAT MAY LEAVE
This table separates the feature, the related data, and the action that starts it.
| Feature | Related data | Activation |
|---|---|---|
| Account and session | Identifier, email, and session tokens managed through Supabase Auth. | When you create an account, sign in, or restore a session. |
| Share an account | Only the chosen account and its functional content; encrypted on the device before it is sent to Supabase. | When you turn on the cloud or share an account. |
| AI receipt analysis | Compressed image, language, allowed currencies, available categories, and basic movement context; a Supabase function requests a proposal from Google Gemini. Free includes 1 scan and PRO offers unlimited scans. | Only when you tap Analyze receipt. Attach, open, edit, and replace do not analyze. |
| Product analytics | Limited pseudonymous usage events through PostHog Cloud EU. | Only if Help improve Tally is on in Settings. |
| Technical diagnostics | Errors, crashes, and technical traces through Sentry, without user-entered financial content. | According to the Send technical errors setting and diagnostic configuration. |
RECEIPTS
Attaching or storing a receipt keeps its image in the app's private storage. Sharing an account does not upload the image; encrypted metadata may be synchronized so it can remain related to the movement.
The image leaves the device only when you request AI analysis. The result is a proposed amount, date, merchant, concept, or category for you to review; it does not replace your decision or save the movement by itself.
SHARED ACCOUNTS
Tally does not synchronize all of your finances by default. If you share an account, the data needed for that account is sent for synchronization and its functional content is encrypted on the device before upload.
A shared account can have edit or view-only permissions. The content is encrypted on the device; this page does not call it end-to-end encryption because protection also depends on member, key, and remote-service management described in the privacy policy.
TRANSPARENCY
WHO IT FITS
You prefer a clear action —sharing, analysis, or enabling a setting— before an external service is used.
You want a manual expense tracker and accept reviewing movements instead of synchronizing them automatically.
You want an explanation that includes the required account and optional providers, not only a privacy promise.
FAQ
We do not make absolute promises. Tally stores functional data locally by default, but it requires an account and some optional features use external services.
No. Tally does not connect bank accounts. PRO import starts from a file you choose and review.
You share only the account you choose. Its functional content is encrypted on the device before synchronization; receipt images remain local.
Only when you tap Analyze receipt. Attaching, opening, editing, or replacing a receipt does not start analysis. A Supabase function requests a proposal from Google Gemini for you to review.
Yes. The privacy policy explains data, providers, retention, rights, receipts, AI, shared accounts, analytics, and diagnostics.
START WITH TALLY
Download Tally and decide what to log, import, and activate.