Privacy

Tallyhouse is a small personal-finance dashboard run by Alexander Novikov. This page says what it stores, who else sees it, and how to get rid of it. Questions or requests: privacy@tallyhouse.net.

What it stores

Your email address and Google account id. Signing in asks Google for openid email and nothing else — not your name, profile or picture.

The Lunchflow and OpenAI API keys you enter. Encrypted (AES-256-GCM) before they are written down; the encryption key lives in the server's environment, not in the database. The OpenAI one is optional — see the AI review below.

A cached copy of your transactions as Lunchflow returns them: date, amount, currency, merchant, description, which account, and the original record.

What you create here: your category rules, manual classifications, the AI review results, and a running total of what the AI review has cost you.

One cookie, sid, which keeps you signed in for 30 days. It is strictly necessary to run the site — there are no analytics or advertising cookies, which is why there is no banner asking you to accept any.

A waiting-list entry — only your email address — if you arrived when signups were full.

Feedback you choose to send, if you use the Feedback button: your message, which page you were on, and your email address so there is a way to answer you. Nothing is recorded unless you write something and press send.

A picture of the page, only if you tick the box for it. The Feedback form can attach an image of the screen as it looked when you opened it, which on this site means your balances, merchant names and amounts. It is drawn in your browser, shown to you in the form before anything is sent, and uploaded only if the box is ticked — leave it alone and the message goes on its own. Whoever runs this instance can see it, which is the point of sending it; it is deleted with your account, or sooner if they clear it.

Who else sees it

Google handles sign-in, and so learns that you signed in to Tallyhouse.

Lunchflow is the service your bank is connected to; Tallyhouse reads your accounts and transactions from them using the key you provide.

OpenAI — worth reading twice. Tallyhouse asks a model to name the transactions your own keyword rules did not match — the ones that would otherwise sit in "Other". A transaction a rule already names is never sent, so the more rules you have, the less of your data leaves. What it sends, per transaction reviewed, is the merchant, description, amount, date and account name, along with roughly a hundred surrounding transactions and per-category totals for context. No merchant name is ever sent to a search engine. This is billed to your own OpenAI key and governed by OpenAI's terms, and OpenAI processes it in the United States.

And one thing you ask for by pressing a button. + rule on a transaction asks a model what the rule should match on. That request carries the transaction itself, the ones whose merchant name resembles it, and up to eighty other payee names from your account — names only, so the model can tell a pattern that catches one shop from one that swallows half your statement. It is sent with storage switched off, so it is not retained in that account, it is billed to your own key, and it happens only when you press the button. Without an OpenAI key nothing is sent: the box is filled in from the merchant's own name instead.

The AI review is optional. It runs only if there is an OpenAI key on your account, and setup does not require one. Without a key, nothing about your transactions is ever sent to a model: no review runs, and the rest of the app — the dashboard, the category rules, the manual classification — works exactly the same. Adding a key in Settings → API keys switches the review on, at which point a review of your recent transactions starts automatically and then keeps up with new ones; how far back that first pass reaches is your choice, and Settings can change it at any time. Removing that choice again means deleting your account, which the section below covers.

One exception, and only if you ask for it. If you set up without an OpenAI key, the categories step offers to propose a starting category list for you. Accepting sends your payee names alone — up to 300 of them, no amounts, no dates, no account details, nothing identifying you — to OpenAI in a single request, on Tallyhouse's own key rather than yours. It is sent with storage switched off, so it is not retained in that account, and nothing from the request is kept here. It happens once per account and never without the button being pressed; decline it and you can type your categories yourself.

Frankfurter supplies historical exchange rates. It is sent a currency code and a date, and nothing about you or your transactions.

Railway hosts the application and its database.

What it never does

No third-party analytics, no tracking, no advertising, and no third-party scripts or fonts — every page loads only from this domain. Nothing follows you between pages or between visits. Your data is never sold, and never shared with anyone beyond the services listed above. Accounts cannot see each other's data.

Counting, and errors

Two things are recorded that are not yours, and this section exists so that the sentence above stays honest rather than convenient.

A daily tally. The app guesses on your behalf — that two equal amounts days apart were one movement of money, that a payment belongs in a category. It keeps a count of how often those guesses are corrected, so a rule that suits one person's bank and not another's can be found and fixed. A count is a name, a date and a number: "a classification was corrected, 3 times, on Tuesday". There is no account in it, no merchant, no amount and no transaction — nothing that could be traced to you, or say what you spent money on, or be joined back up with anything that could.

Failures. When something breaks, here or in your browser, the error message and the technical trace of where it happened are recorded, along with which view you were on — "the transactions page". Never what was on it: not the numbers, not the merchants, not the page itself. One entry per distinct fault however many people hit it, deleted after 90 days. Without this, a page that breaks for you is something we only learn about if you write in.

Keeping and deleting

Everything is kept until you remove it. Settings → Account → Delete erases your account and everything attached to it — keys, rules, classifications, AI reviews, cached transactions, any feedback you sent and the pictures attached to it, and your sessions on every device. Historical exchange rates are kept, because they are shared between accounts and say nothing about you. The counts and the error log are kept too, and for the same reason: there is nothing of yours in them to delete.

Settings → Export all data gives you the whole lot as a single file whenever you want it, as JSON or as a CSV a spreadsheet can open. Expired sessions are cleared automatically.

Your rights

Under UK GDPR you can ask for a copy of your data, have it corrected or erased, take it elsewhere, or object to it being processed. The export and delete buttons in Settings cover most of that immediately; for anything else, email privacy@tallyhouse.net. The lawful basis is performing the service you asked for. If you are unhappy with how this was handled you can complain to the Information Commissioner's Office at ico.org.uk.

Changes

Last updated 26 August 2026. Anything material that changes will be described here.