Legal

Privacy Policy

Last updated: April 23, 2026

TallyMail ("we", "our", or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, store, and share your information when you use TallyMail ("the Service"). By using TallyMail, you agree to the practices described in this policy.

1. Information We Collect

Account Information

When you register, we collect your name, email address, and — if you sign in via Google — your Google profile picture and Google account ID. We do not store your Google password.

Email Content (Receipt & Transaction Emails)

TallyMail works by receiving email messages that you forward to your assigned TallyMail inbox address. The content of these forwarded emails — including email body text, subject lines, and sender information — is processed by our AI to extract expense data. We store a brief summary (snippet) of each parsed email. We do not store full email bodies permanently after parsing.

Expense Data

We store the structured expense data extracted from your emails: amount, merchant name, category, date, payment method, currency, and a one-line description. This data is linked to your account.

Usage Data

We may collect basic usage logs (e.g., when you log in, pages visited) for security and service improvement purposes. We do not use third-party analytics trackers.

2. How We Use Your Information

To Provide the Service

Your email content is sent to OpenAI's API (GPT-4o-mini) for AI-based expense parsing. OpenAI processes the text to extract structured expense fields. We do not use your data to train OpenAI models — this is governed by OpenAI's API data usage policy.

To Show Your Dashboard

Parsed expense data is displayed in your personal dashboard, including charts, totals, and transaction history.

To Send System Emails

We may send you account-related emails such as password reset links, email verification, and Gmail forwarding confirmation instructions. We do not send marketing emails unless you explicitly opt in.

To Improve the Service

Aggregated, anonymized statistics (e.g., number of receipts processed) may be used to improve TallyMail's features. This data cannot be linked back to any individual user.

3. Third-Party Services

OpenAI

Email text content is sent to OpenAI's API for parsing. By using TallyMail, you acknowledge that email content will be processed by OpenAI. OpenAI's privacy policy applies to how they handle API data. Visit openai.com/privacy for details.

Google OAuth

If you sign in with Google, Google shares your basic profile information (name, email, profile photo) with TallyMail. TallyMail does not receive access to your Gmail mailbox, Google Drive, or any other Google services beyond what you explicitly consent to.

Email Hosting

Forwarded emails are received by our IMAP email server. Email content is processed and then discarded after parsing — it is not retained on the mail server permanently.

4. Data Storage & Security

Storage

Your account data and expense records are stored in a secured database. We use industry-standard security practices including encrypted connections (HTTPS/TLS) for all data transmission.

Retention

We retain your expense data for as long as your account is active. You may delete individual expenses or your entire account at any time. Upon account deletion, all your personal data and expense records are permanently removed from our systems within 30 days.

Breach Notification

In the event of a data breach that affects your personal information, we will notify you via email within 72 hours of becoming aware of the breach.

5. Your Rights

Access & Portability

You can view and export all your expense data at any time via the Expenses page (CSV export). You may request a full data export by contacting us.

Correction

You can edit any expense record directly from your dashboard.

Deletion

You may delete individual expenses or your entire account from your Profile settings. Account deletion removes all associated data permanently.

Data Processing Objection

You may stop forwarding emails to TallyMail at any time by removing your Gmail filters. No new emails will be processed after that.

6. Children's Privacy

Age Restriction

TallyMail is not intended for use by individuals under the age of 13. We do not knowingly collect personal information from children. If we become aware that a child under 13 has provided us with personal data, we will delete it immediately.

7. Changes to This Policy

Updates

We may update this Privacy Policy from time to time. We will notify you of material changes by sending an email to your registered address or by displaying a prominent notice in the app. Your continued use of TallyMail after changes are posted constitutes acceptance of the revised policy.

Contact Us

If you have any questions about this Privacy Policy or how we handle your data, please contact us at:
support@tallymail.app