TallyVally

Privacy policy and support for the TallyVally expense tracker

View the Project on GitHub indxneo/tallyvally-legal

Privacy Policy — TallyVally

Effective date: July 22, 2026 Last updated: September 20, 2026

Applies to: the TallyVally mobile app for iOS and Android.


The short version


1. Who this policy is for and who we are

This policy explains how the TallyVally app (“the app”, “TallyVally”) handles your information. The app is published by Alisher Serikbayev (“we”, “us”, “the developer”). You can reach us about privacy at alishersv.dev@outlook.com.

TallyVally is a personal expense and asset tracker. Its design principle is data sovereignty: your financial history stays on your device by default, and anything that leaves the device is disclosed here.

2. Where your data lives

TallyVally stores your data in a local database (SQLite, via Drift) inside the app’s private storage on your device. This includes:

There are no user accounts, no sign-in, and no cloud copy of this data under our control. We cannot see your ledger.

3. What leaves your device, to whom, and why

Only two features send data off your device, and both send it to the same recipient: Google’s Gemini AI (generativelanguage.googleapis.com). The requests are routed through our backend proxy — a Supabase-hosted Edge Function — which forwards them to Google and returns the result. The proxy exists so that the Google API key is never embedded in the app; it is infrastructure, not a place where your data is stored.

3a. Scanning a receipt (AI receipt OCR)

When you scan or upload a receipt, the app sends the receipt itself to Google Gemini — either the photo you took or chose, or a PDF you uploaded from Files. Gemini reads it and returns the structured fields (store, date, totals, line items, and — if printed on the receipt — the payment method and card last-4). The extracted result is then saved on your device.

A PDF is sent in full, every page. If a document holds more than the one receipt you meant to scan, everything printed in it is part of what is sent.

Important and honest detail: because the whole receipt is sent for reading — the entire photo, or every page of the PDF — anything visible on it is part of the transmission. If your receipt prints the last four digits of your card and the payment method, those are present in the image and are extracted by Gemini. This is why we disclose Payment Info as data that can leave the device. We never send a full card number, PIN, CVV, expiry, or bank-account number — those are not stored on the receipt and are not handled by the app.

Three small technical values travel with a scan, and none of them is a receipt field. Your phone’s calendar date is sent to Google along with the image, so that a receipt printing no date of its own is filed on your day rather than the server’s. Your home-currency setting (for example USD) and a free-or-premium flag go only as far as our own proxy — the first so it can look up that day’s exchange rate, the second so it can manage its own AI budget. None of the three identifies you, and only the date reaches Google.

Receipt scanning is user-initiated: nothing is sent unless you choose to scan or upload a specific file.

3b. Asking the financial assistant (AI chat)

When you ask the in-app assistant a question, the app sends to Google Gemini:

  1. Your typed question (and the recent back-and-forth of the current conversation), and
  2. A summary of your spending used to ground the answer in your real data.

By default, that summary includes aggregate figures (your total spend, number of transactions, average transaction value, total savings, and spending by category) and a short list of the items you buy most often, by name. When your question names a particular store, item or time period, the store names and shopping dates needed to answer it are included as well.

One detail worth being plain about: the list of your most-purchased item names is part of every cloud chat question, not only the ones that mention an item. Store names and dates are not — those travel only when your own question or the recent conversation refers to them. If your receipts record purchases you would rather not have read by an AI service, turn on Aggregate-only AI mode (Section 3c), which sends no item names at all, or use on-device chat where your iPhone supports it, which sends nothing for an answer. On-device chat is an iPhone feature; Android has no on-device AI option and always uses the cloud assistant described above.

The chat path never sends your card last-4 or payment method. The grounding summary is built so that card and payment fields are excluded — they are simply not part of what the chat feature reads.

3c. Aggregate-only chat mode (opt-in, for stricter privacy)

In Settings → Chat & Data you can turn on “Aggregate-only AI mode.” When it is on, the chat feature sends only totals and category breakdowns — no item names, no store names, and no dates leave your device. Answers become less specific in exchange for sending the minimum possible data. This setting is off by default, so the assistant has the detail it needs unless you choose otherwise.

3d. What we do not send anywhere

4. How Google handles the data we send it

The receipt images and chat content described in Section 3 are processed by Google’s Gemini API. Google’s handling of that data is governed by Google’s own API terms and privacy commitments for the API tier in use, not by us.

We are honest about the limit of our knowledge here: confirming and contracting a specific no-retention / no-training Gemini tier is an operational step the developer must complete, and until that is confirmed we do not claim that Google does not retain or use this data. We send Google the minimum needed for the feature to work, we never attach an account or identity to it (there are no accounts), and the aggregate-only mode (Section 3c) lets you reduce what is sent to totals only. For details of Google’s practices, see Google’s API terms and privacy documentation.

5. No tracking, no ads, no third-party analytics

TallyVally contains no advertising SDKs, no behavioral-analytics SDKs, and no cross-app/cross-site tracking. We do not build advertising profiles, and we do not use the Apple “tracking” mechanisms (App Tracking Transparency is not invoked because we do not track). The iOS privacy manifest declares NSPrivacyTracking = false and an empty tracking-domains list, consistent with this statement. On Android the app requests no advertising identifier and contains no advertising or analytics library of any kind.

The one third-party SDK in the app is Firebase Crashlytics, and it is here to report crashes, not to watch you. We are naming it rather than hiding it behind the word “analytics”, because it is a Google SDK and you are entitled to know it is there. What it is not: it records no screen views, no taps, no sessions, and no usage patterns, and it builds no profile. Firebase’s own privacy manifest declares that it collects “Crash Data” and “Other Diagnostic Data”, both not linked to your identity and both not used for tracking — which matches what we have enabled. Section 3d describes exactly what a report contains.

6. Data retention and deletion

7. Security

No method of electronic storage or transmission is perfectly secure, but we minimize what leaves the device and protect what remains on it.

8. Device permissions we request

These permissions are used only for the receipt-scanning feature you initiate, and only on the specific image you choose. We do not access your camera or photo library in the background.

On Android the app declares no camera, photo, or storage permission at all. It asks only for internet access and for billing through Google Play. Photographing a receipt hands the job to your phone’s own camera app, and choosing a photo or a PDF goes through Android’s own picker, which passes back only the one file you chose.

9. Children

TallyVally is a general-audience financial tool and is not directed to children. We do not knowingly collect personal information from children.

10. International users and data transfer

If you use the app outside the regions where Google processes Gemini API requests, the receipt/chat data described in Section 3 may be processed in another country (for example, the United States). By using the AI scanning and chat features, you understand that this processing occurs as described here.

11. Your choices and controls

12. Changes to this policy

If we change how the app handles data, we will update this policy (and the “Last updated” date) and, where the change is material, surface it appropriately. The version published at https://indxneo.github.io/tallyvally-legal/ is the authoritative version.

13. Contact

Questions about this policy or your data: alishersv.dev@outlook.com.

This policy is governed by the laws of the State of Illinois, United States.