// PRIVACY POLICY
PRIVACY.
Tally. is a tally for two. Or three. Or twelve. A way of staying in touch with the people who matter, around something low-stakes you both keep score on. We try to hold as little data as possible, and to be specific about everything we do hold. This page explains what we collect, why, who else sees it, and what choices you have.
1. Who we are
Tally. is built and operated by Tom Fletcher, an individual based in the United Kingdom ("we", "us"). Tally. is an independent project, not a registered company. For the purposes of UK GDPR, the data controller is Tom Fletcher. You can reach us at hello@gettally.co.uk.
2. What we collect
Account & identity
- Email address. Required. We use it to sign you in via a one-time code (the “magic link”).
- Display name and handle. Your display name (up to 16 characters) and a public handle (e.g.
fletch-7k2x) auto-generated when you sign up. The handle is how friends find you. - Optional profile details. Player colour, usual order, timezone, age-confirmation flag. All optional, all under your control in the app.
- Apple / Google Sign-In identifier (only if you choose to sign in that way). We store the opaque user ID Apple or Google gives us, not your email at those providers, unless you also let them share it.
Tallies & marks
- The tallies you create or join, who’s in them, and the marks logged inside them.
- Witness photos you attach to a mark (stored as image files; see “Photos” below).
- Forfeits, settings, and metadata for each tally.
Device & session
- Device info: a device identifier we generate, the device model and name, iOS version, and the Tally app version. We use this to keep sign-ins safe and to debug platform-specific bugs.
- Push token, if you grant notification permission. Used to send the notifications you’ve enabled, nothing else.
- IP address and user agent for each session. Stored against the session record so we can spot abuse and so you can revoke a session from another device.
- Sign-in tokens (refresh tokens). Stored as a one-way hash, so we can verify them but can’t read them.
- Last seen at, so the app can show “active recently” and clean up stale sessions.
Photos
- Witness photos and avatars you upload are stored as files in our object storage (AWS S3). Photos are private by default: we hand out short-lived signed URLs to the people who should see them.
- Witness photos are automatically deleted after 90 days.
Diagnostics
- If you opt in via iOS, Apple sends us aggregated crash and usage reports through App Store Connect. These do not contain your name, email, contacts, or marks.
- Our backend keeps structured server logs (method, path, status, latency, IP for the session). Sensitive fields (passwords, codes, tokens) are redacted before anything is written.
- We do not use third-party analytics SDKs (no Mixpanel, PostHog, Segment, Sentry, etc.).
3. What we don’t collect
- We don’t ask for your real name, phone number, or address.
- We don’t track you across other apps or websites.
- We don’t sell, rent, or share your data with advertisers.
- We don’t place advertising in the app.
- We don’t use third-party analytics SDKs.
4. Why we hold it (legal bases)
Under UK GDPR, we rely on the following legal bases:
- Performance of a contract (you’ve asked us to provide the app): account, identity, tallies, marks, photos, devices, sessions.
- Legitimate interests: anti-abuse logging (IP / user agent on sessions), keeping the service running, fixing crashes. We’ve assessed these as low-impact and have not found any rights that override them.
- Consent: push notifications (you grant iOS permission), opt-in diagnostics (via iOS).
- Legal obligation: if we’re ever ordered by a UK court or regulator to retain or disclose specific records.
5. Who else sees your data (sub-processors)
We use a small number of providers to run the service. We send them only what they need:
- Hostinger provides the virtual private server the Tally backend runs on. The backend and the Postgres database that stores your account, tallies, marks, and session records run on that server, inside a private network we set up and manage ourselves. Hostinger supplies the infrastructure but has no application-level access to your data. Data centre region: United Kingdom.
- Amazon Web Services (S3) stores the photo files you upload (witness photos and avatars). Bucket region: London (eu-west-2), United Kingdom.
- Amazon Simple Email Service (SES) sends our transactional emails: sign-in codes and the welcome email. SES receives your email address, the email content, and standard delivery metadata. Region: London (eu-west-2), United Kingdom.
- Apple covers the App Store (download & receipts), the Apple Push Notification service (APNs, which delivers notifications to your phone), and optionally Sign in with Apple.
- Google is involved only if you choose Sign in with Google. Google receives the sign-in request; we receive an opaque user identifier back.
That’s the entire list. We do not pass your data to advertisers, brokers, or analytics resellers.
6. How long we keep it
- Sign-in codes (one-time email codes): hashed; deleted shortly after they’re used or expire.
- Refresh tokens (sign-in sessions): up to 30 days after they expire or you sign out, then deleted.
- Witness photos: 90 days, then permanently deleted from S3.
- Pending photo uploads that never complete: cleaned up after 15 minutes.
- Your account & tallies: kept while your account is active. If you delete your account, see section 7.
- Server logs: a rolling window of 30 days, used for debugging and investigating abuse. Sensitive fields (passwords, codes, tokens) are stripped before logs are written.
7. Deleting your account
You can delete your account from inside the Tally app. When you do:
- Your sign-in sessions and device registrations are revoked immediately.
- Your account is marked deleted. For 30 days you can change your mind: sign back in with the same email to restore it.
- After 30 days, your identifying details (email, display name, handle, device info) are permanently scrubbed. The marks themselves stay attached to the (now anonymised) account so that the tallies your friends are in don’t fall apart.
- If you want a full erasure beyond that, including the anonymised mark records, email hello@gettally.co.uk and we’ll handle it manually.
8. Age
Tally. is intended for adults, in line with our App Store age rating. We don’t knowingly collect data from anyone under that age. If you believe a minor has used the app with us, please contact us and we’ll remove whatever we can.
9. Your rights
If you’re in the UK or EEA, you have the right to:
- access the personal data we hold about you;
- have it corrected if it’s wrong;
- have it erased (see section 7);
- object to or restrict how we use it;
- receive a copy of it in a portable format;
- withdraw consent at any time where we’re relying on it (e.g. revoke push notification permission in iOS Settings).
Email hello@gettally.co.uk for any of these. You also have the right to complain to the UK Information Commissioner’s Office (ICO) at ico.org.uk, though we’d rather you came to us first so we can fix it.
Similar rights apply in some other places (California’s CCPA, etc.), and the email above is the same regardless of where you’re writing from.
10. International transfers
The backend, database, photo storage, and transactional email are all hosted in the United Kingdom. The only data that routinely leaves the UK is what Apple and Google handle on their own platforms: push notifications via Apple’s APNs and (if you use them) Sign in with Apple or Sign in with Google. Those transfers rely on the UK-US Data Bridge / EU-US Data Privacy Framework and Standard Contractual Clauses, as appropriate.
11. Security
Sign-in codes and refresh tokens are stored as one-way hashes, so we can verify them but not read them. Connections to the backend use HTTPS. Photo URLs are short-lived and signed. We can’t promise perfect security (nobody can), but we keep the surface area small on purpose.
12. Changes to this policy
We’ll update this page when the app changes in a way that affects your privacy. The “Last updated” date at the top tells you when we last touched it. For material changes we’ll also flag it in-app.
13. About this website
This site (gettally.co.uk) is a static brochure. It sets no cookies, runs no analytics, and serves no advertising. The only third-party request it makes on your behalf is to Google Fonts, which serves the brand typefaces and, as a CDN, sees your IP address. If that matters to you, your browser’s privacy mode or a Pi-hole-style blocker will stop it without breaking the site.
14. Contact
Questions, requests, or anything else: hello@gettally.co.uk.
// END OF DOSSIER