Privacy Policy
Last updated September 17, 2026
Tally helps groups count down to trips, share trip photos, and keep a shared record of spending and settlements. This policy describes the information Tally handles and the choices available to you.
Information Tally handles
- Account information. You can sign in with Apple or a verified phone number. Apple may provide an Apple-specific account identifier and, if you choose to share it, your name. Tally never receives your Apple password. If you use phone sign-in, Tally stores your verified phone number to operate and secure your account.
- Trip and group information. This includes trip names, dates, locations, membership, invitations, and the display names added for guests.
- Invitations. Tally creates a shareable join link. You choose who receives it in the iOS share sheet. Tally does not send email or text invitations on your behalf and does not access your contacts.
- Expense records. This includes descriptions, amounts, currencies, dates, payers, split participants, and settlement entries. Tally records these entries but does not process payments between trip members.
- Trip photos. Photos you upload to a trip, plan, or profile are stored so the appropriate people can view them. Images generated for sharing are created on your device and leave Tally only when you choose to share them.
- Discussion content. Messages and comments you add are stored in the trip conversation and are visible to that trip’s members.
- Receipt photos. Tally reads receipts with Apple Intelligence on Private Cloud Compute: receipt photos go from your iPhone to Apple’s servers to read the total, details, and items, and are not sent to Tally’s servers or any other AI provider for reading. Receipt photos and unfinished expense details, including what was read from them, are saved privately to your Tally account on Tally’s servers, visible only to you, until you save them as an expense or delete them; this iPhone keeps a copy so they work offline, and they appear on your other devices signed in to the same account. When you save an expense with a receipt, its photos are shared with that trip’s current members, who can view them with the expense. Shared receipts are deleted when the expense is deleted or when the person who shared them deletes their account. Deleting your account removes your local captures. If you add an email address to your account, Tally sends a code to confirm it and uses it to match receipts you email to Tally to your account. Emailed receipts are received by Cloudflare and kept privately on Tally’s servers, visible only to you, until the app adds them to your Drafts, and never longer than 30 days.
- Trip tools. Checklists, assignments, completion, reservation details, and documents you explicitly upload are shared with active trip members. Booking sources are kept on your device unless you attach them to a trip or read them with Apple Intelligence, which sends their text and images to Apple’s Private Cloud Compute to suggest booking details. Review suggestions before saving.
- AI features. Receipt reading, booking import, plan suggestions, and the daily trip note use Apple Intelligence on Private Cloud Compute. Apple processes each request only to answer it, does not store it or use it to train models, and publishes Private Cloud Compute for independent inspection. Tally does not receive or store AI requests or responses. These features need Apple Intelligence on iOS 27 or later and are subject to Apple’s daily usage limits.
- Private import drafts. Sources shared to Tally are kept in protected local storage for your signed-in account. Receipts remain saved until you delete them. Other pending share intake expires after seven days, and signing out or changing accounts clears queued booking and document sources and booking drafts.
- Pro purchases. Apple processes optional Pro purchases. Tally stores verified transaction identifiers, account associations, subscription status, and trip grants to deliver and restore access. Tally does not receive your payment-card details.
- Service records. Tally stores timestamps and limited operational records needed to deliver invitations, synchronize edits, retry uploads, prevent duplicate financial entries, and complete account deletion.
- Diagnostic records. When an unexpected app error occurs after you sign in, Tally may store a short error reference, the failed operation, a safe error category and code, app and operating-system versions, and an account identifier supplied by the server. These records do not include trip content, names, phone numbers, invite links, payment details, request payloads, or raw server messages.
How information is used
Tally uses this information only to provide and protect the app: authenticate accounts, synchronize trips, calculate group balances, share information with trip members, operate invitations, store photos, and respond to deletion requests. Tally does not sell personal information, run third-party advertising, or use trip content for targeted advertising.
Who can see information
Members of a trip can see that trip’s details, member names, photos, spending, balances, and settlements. A person with a valid invite can preview the associated invitation and choose whether to join. Anything you export through the iOS share sheet is shared at your direction with the people or apps you select.
Service providers
Tally uses Apple and Supabase for account authentication, Supabase for database, realtime synchronization, server functions, and file storage, Bird to deliver phone verification codes, Vercel to serve Tally’s website and universal invite links, Cloudflare to receive emailed receipts and send email confirmation codes, and Apple Private Cloud Compute for AI features. These providers may process phone numbers, email addresses, and technical request information as needed to operate and secure their services.
Retention and deletion
Trip content remains while the trip or account is active unless an authorized member removes it. Expense creators and trip owners can permanently delete an expense. You can request account deletion in Settings → Delete Account. Trips you solely own are deleted with your account. If other people share a trip you own, you can choose another member to receive ownership as part of account deletion.
When your account is deleted, Tally removes your profile, linked sign-in credentials, invitations, and uploaded photos. Expense and settlement records in trips retained by other members remain as shared group history. Your stored display name remains with those records so the group can understand its financial history, but the membership is disconnected from your account. Limited non-identifying deletion and cleanup records may remain to prove and finish the request.
Documents remain available to the group when their uploader leaves a trip. Deleting your account removes the documents you kept personal and leaves the ones you shared with a trip in place for its other members, no longer linked to you. Verified purchase records may remain to support access, refunds, and purchase recovery after account deletion.
Diagnostic records are automatically deleted after 30 days. Tally may retain them for less time when they are no longer needed to investigate reliability.
Security
Tally uses authenticated access controls and encrypted network connections. No service can promise absolute security, so protect your sign-in account and share trip invitations only with people you trust.
Children
Tally is not directed to children under 13 and is not intended to collect their personal information.
Changes and contact
If this policy changes, the updated policy will appear here with a new date. For privacy questions or requests, use the Tally support contact provided with the app or on its App Store product page.