Your records stay yours.
Privacy notice · Pilot · October 3, 2026
What the service handles
The sample contains fabricated records. For private audits, we process your invoice charges, agreed rates, warehouse activity, file names and source row references. Native file preparation also saves original CSV, Excel and attached PDF files, extracted cells, document hashes, mapping choices, human-entered rates and corrections in private account storage. Original values remain separate from your corrections. We save the reviewed snapshot and findings so you can revisit and export them. Column mappings and your theme preference may be saved on your device; invoice contents are not stored in browser local storage.
Accounts and payments
Supabase provides account authentication and private data storage. Railway hosts the application. These services receive the information needed to provide their functions.
Paddle is our payment processor and merchant of record: it runs checkout, takes payment, handles tax, issues receipts and manages your subscription. To set up billing we send Paddle your account email and an internal account reference. Paddle collects your payment details and billing address itself and handles them under the Paddle privacy notice; this application never sees or stores card numbers.
Emails
Resend sends our emails: sign-in links and codes, and the reminders you choose on your account page. A reminder carries your email address, the name of the check, the warehouse and the date you set. It never includes amounts or invoice lines. Every reminder has a link to turn it off.
Suggestions from an AI model
To save you typing, Tally can ask an open-weight model, through OpenRouter, for four kinds of suggestion. When your invoice or activity file names a fee differently from your rate card, we send the unmatched fee names and your rate codes, and ask which rate each one matches. When we can't find the provider, warehouse or account in your files ourselves, we send each file's name, its column headings and the short lines printed above its table (such as an invoice's letterhead or account line), and ask the model to copy those details out. When a spreadsheet is laid out in a way we can't read ourselves (titles below a logo, a totals block under the table), we send its file name and first 30 rows with every digit replaced by 9, so the model sees labels and the shape of each value but no amount, quantity, date or ID, and ask which row holds the column titles and which column holds what. Your browser then reads the rows itself. From spreadsheets we never send real amounts, quantities or dates.
When you add a PDF, your browser reads its text; the PDF file itself is never sent to the model. If the PDF has text, we send the text of every page, prices and dates included, and ask the model whether it is a rate card and, if it is, to list each price rule. We keep only prices printed on the page the model cites, and they reach a check only when you run it with them in your rates. Invoices and other PDFs give no prices this way and stay as evidence. Scanned pages without text are not sent.
Every request requires a provider that keeps no copy of the request and does not train on it. A suggestion changes nothing until you accept or keep it, the model may only copy details that appear in what we sent, and you can always fill everything in yourself.
ChatGPT
When you use the ChatGPT integration, requested findings and records supplied through the conversation are also handled by ChatGPT under its policies. Deleting an audit here does not delete your ChatGPT conversation. We do not train a model on your invoices.
Retention and deletion
Saved audits and drafts expire after 90 days. An original file stays available until 90 days after the latest new draft or saved audit that references it; editing an existing draft does not renew its expiry. Deleting a draft does not delete originals shared with a saved audit. Expired records become inaccessible and are removed by scheduled cleanup. You can delete an audit sooner or delete your account from the account page. Account deletion cancels the subscription immediately. Payment and legally required records may remain with payment providers. Backup deletion follows the storage provider’s retention schedule.
Files you let us keep
After a check, or when we could not read a file, we may ask whether we can keep a copy. Nothing is kept unless you press keep. A kept copy is stored privately, apart from your checks, and only the Tallyfive team opens it, to test and improve how we read bills; we may run it through the same zero-retention reading described above. We never share it, publish it or train a model on it. It is deleted after 12 months, when you delete it on the account page, or when you delete your account.
Support
The data controller is Blocklift Limited, company number 136232C. For access, correction or deletion requests, contact [email protected].