THE DETAILS
Privacy policy
Effective October 9, 2026 · Version 1.2
This policy describes data handling in the current TallyClip application. The operator of a deployed instance is responsible for its infrastructure and any additional services it configures.
1. Information the application handles
TallyClip handles the bank statements you upload, filenames and file metadata, extracted account and transaction information, your corrections, balance checks, and review records. These records let you review a statement and produce a versioned export.
For registered accounts, the application also handles a stable user identifier, email address, workspace membership, subscription status, and page-usage records. Configured authentication and billing providers may process information needed for their services.
2. How your information is used
Document information is used to extract transactions, check balances, display source information, save corrections, and generate the export you request. Account and workspace information is used to control access, manage page allowances and access periods, and administer subscriptions.
PDF text extraction and OCR run on the application host. External AI processing is disabled by default. When the operator explicitly configures an external AI provider, the application sends locally extracted statement text to that provider for structured extraction. It does not send the original PDF or image file to that provider. The upload panel identifies external processing when it is enabled.
3. Storage and access
Uploaded files and statement results are stored in a private data directory on the application host. Server-side access checks restrict statement operations to the owning workspace. This version uses a single-host storage design; the deployed operator is responsible for protecting that host and any backups it creates.
4. Configured service providers
When enabled, Supabase supports email and Google authentication. Signing in through Google involves Google and the configured authentication provider. Stripe handles payment checkout and the customer billing portal. TallyClip stores subscription references and status, rather than full payment-card information. Statement content is not needed for authentication or billing.
An optional external AI provider receives extracted statement text only when the operator explicitly enables and configures that integration. Its own processing, retention, and privacy terms apply to that text. The deployment operator is responsible for identifying the provider and its terms to users. This implementation does not make a no-retention or no-training guarantee on behalf of an external provider.
5. Retention and deletion
Guest statements expire after 24 hours. Registered-account statements and extracted results default to 30 days. You can delete a statement from the workspace before its expiry; the application cleanup process removes expired document data.
Account, usage, and payment-reference records are separate from statement retention. Provider records follow the relevant authentication, billing, or optional AI provider’s terms. Deleting local statement data does not delete data retained by those providers and does not cancel a subscription.
6. Cookies and session information
TallyClip uses session information to maintain guest and account access. Authentication may require cookies. This implementation does not include advertising trackers. Additional analytics or services added by a deployment operator should be disclosed separately.
7. Your choices
You can review and correct extracted data, delete statements, and manage available account and billing settings. Upload only documents you are authorized to process. For account deletion or questions about a deployed service, contact its operator through the support channel provided with that deployment.
8. Changes to this policy
Data-handling changes should be reflected in this page before they are introduced. The effective date above identifies this version. See Security for the current implementation boundaries and Terms of use for service rules.