Effective date: July 29, 2026
TallyMint is built by ks-bytebox and comes in two forms, which handle your data very differently. This policy covers both, and says clearly which parts apply to which.
If a section below does not name a product, it applies to both.
The desktop app stores all of your financial data (accounts, transactions, budgets, categories, and reports) in an encrypted file on your computer, and never sends it to us. That file is encrypted with AES-256 and opened with your master password: the key to it is held in a small key file beside the ledger, wrapped with AES-256-GCM under a key derived from your password with Argon2id, and the password itself is never stored. Your saved bank connection credentials and your license data are encrypted again inside the ledger. See our security page for the full detail.
For the desktop app, we do not operate cloud servers that store your financial data. We cannot access, read, or recover it. You are in full control of your ledger and can back it up however you choose; because the key file is part of it, back up the folder rather than the data file on its own.
When you purchase TallyMint and enter your license key, the app performs a one-time activation request to our payment provider, Dodo Payments, to validate the key. This request includes:
After successful activation, the license status is cached locally. TallyMint does not phone home on every launch.
TallyMint periodically checks for software updates by contacting tallymint.app/api/update/. This request includes:
No user data, license keys, financial information, or personally identifiable information is sent during update checks.
If you choose to connect your bank accounts in the desktop app, TallyMint uses SimpleFIN Bridge, a third-party service, to download transactions. Here is how it works:
SimpleFIN has its own privacy policy governing how it handles your banking connection. We encourage you to review it at simplefin.org.
TallyMint Web is a hosted service, so unlike the desktop app it does store your data on our infrastructure. This is the part of the policy that matters most if you subscribe, so it is spelled out in full.
When you create an account we store your email address, your first name if your sign-in provider supplies one, and your browser's time zone (so that dates, due dates, and projections are computed against your local calendar rather than ours). Sign-in itself is handled by Clerk, our identity provider, which holds your credentials. We never see or store your password.
We store the ledger you build: accounts, transactions, categories, splits, transfers, budgets, recurring bills, savings goals, loan terms, and investment holdings with their cost basis. This data is encrypted in transit over TLS and encrypted at rest by our database provider. Every table holding customer data has row-level security enforced by the database itself, keyed to your account, and the application's database role cannot bypass it, so isolation between customers does not depend on application code getting a filter right.
If you connect a bank, TallyMint Web uses Plaid. You authenticate with your bank on Plaid's own secure screen and choose which accounts to share. We never receive your bank username or password. We receive an access token, which we store encrypted with AES-256-GCM under a key held separately from the data, and we use it to read balances, transactions, and investment holdings. Access is read-only. TallyMint cannot move money, initiate payments, or change anything at your bank. When your subscription ends, or when you disconnect a bank yourself, we delete the connection at Plaid. Plaid's handling of your data is governed by its own end user privacy policy.
Card details never touch our servers. Payments are processed by Dodo Payments, our merchant of record. We store your subscription status, plan, renewal date, and their customer and subscription identifiers so we know what you are entitled to.
We send transactional email about your account: payment receipts and failures, notices before data is removed after a long lapse, and replies to support requests. These are sent through Resend. Security notices, such as an alert when a new device signs in, are sent by Clerk. You cannot opt out of essential transactional and security email while you hold an account, because it is how we tell you about your own money and access.
These are the third parties that process data on our behalf, and what each one is for:
We do not sell, rent, or trade your data, and we do not use it to build advertising profiles. Our only revenue is the subscription you pay.
While your subscription is active, we keep your data so the product works. If your subscription ends, your account becomes read-only and we keep your data for 12 months so that a lapse, a gap, or a change of heart does not cost you your history. We email you before anything is removed. Bank connections are deleted when the subscription ends, not held for 12 months, because a live connection has an ongoing cost and no purpose once you have stopped syncing.
You can export your entire ledger to QIF or CSV at any time, including while read-only, without asking us for anything. You can ask us to delete your account and its data at any time by emailing support@tallymint.app, and we will confirm when it is done. You can correct your own data directly in the app, since it is your ledger.
The TallyMint marketing website (tallymint.app) uses Microsoft Clarity to understand how visitors find and use the site: the referring site, pages visited, and anonymized interaction heatmaps and session replays. Clarity sets first-party cookies on this website only. This applies to the marketing site, not to either app: the desktop application contains no analytics, telemetry, or tracking of any kind, and the TallyMint Web application (app.tallymint.app) carries no Clarity or advertising tracker either. For details on how Microsoft processes this data, see the Microsoft Privacy Statement.
The website also offers an optional email signup for update announcements. If you submit your email address, we store it (along with the date and country of signup) and use it only to send occasional announcements about major TallyMint features and releases. We never sell or share the list, every email includes an unsubscribe option, and you can request removal at any time by emailing support@tallymint.app.
To be explicit, neither version of TallyMint collects:
And specific to the Windows app, we additionally do not collect your financial data at all: no transactions, balances, or account numbers, because they never leave your machine.
We do not sell, share, rent, or trade your data to third parties.
The Windows app communicates with:
TallyMint Web uses the service providers listed in the TallyMint Web section above (Cloudflare, PlanetScale, Clerk, Plaid, Dodo Payments, Resend, and EODHD).
Separately, the marketing website uses Microsoft Clarity for visitor analytics, as described in the Website section above.
Windows app: your data lives entirely on your computer, so you control retention. Deleting the TallyMint data file permanently removes all your financial data. We have nothing to delete on our end because we never had it.
TallyMint Web: we keep your data while your subscription is active, and for 12 months after it ends, with email notice before anything is removed. Bank connections are deleted as soon as a subscription ends. You can request deletion sooner at any time.
TallyMint is not directed at children under 13, and TallyMint Web is not intended for anyone under 18, since it requires a payment method. We do not knowingly collect information from children.
If we update this privacy policy, we will post the revised version on this page with a new effective date. Material changes will be communicated through the application or website.
If you have questions about this privacy policy, contact us at support@tallymint.app.