TALLYMAP
how it worksdaresprivacyterms
Get the app
the fine print, unfined

PRIVACY POLICY

Your bank does the counting. Your phone keeps the tally. We keep as little as we can get away with.

Effective September 8, 2026Applies to the TallyMap iOS app & tallymap.app

Sections

  1. 0The short version
  2. 1Who we are
  3. 2What we collect
  4. 3What we don't collect
  5. 4Where your data lives
  6. 5How we use it
  7. 6Who we share it with
  8. 7Friends & dares
  9. 8Deleting your data
  10. 9Retention
  11. 10Security
  12. 11Your rights
  13. 12Children
  14. 13This website
  15. 14Changes
  16. 15Contact

0.THE SHORT VERSION

Read-only. You link a bank through Plaid. TallyMap can see transactions; it can never move money, log in as you, or see your bank password.

On your phone. Your transactions and everything the app computes from them (places, strokes, stickers, streaks) are stored on your iPhone, not on our servers. Our servers pass transactions through and keep only what is needed to fetch the next batch.

No GPS. Every mark on the map comes from the merchant's location in your bank data. We never ask for or track your phone's location.

Counts, never amounts. When you use friend features, friends see tally strokes, streaks, and dare results. They never see dollar amounts.

No ads, no selling, no tracking. We don't run ads, sell data, or use analytics or advertising SDKs that track you across apps.

One tap to leave. Delete your account in the app and we erase your account, revoke your bank connections at Plaid, and wipe your phone's data.

The rest of this policy says the same things in more detail. If anything here conflicts with the short version, the detailed sections control.

1.WHO WE ARE

TallyMap is made and operated by FinShark ("FinShark", "we", "us"). This policy covers the TallyMap iPhone app, its widgets, and the website at tallymap.app (together, the "Service"). You can reach us at hello@tallymap.app.

FinShark is the "controller" of the personal data described here, meaning we decide why and how it is processed. Plaid and Apple also act as independent controllers for the parts they handle (see Section 6).

2.WHAT WE COLLECT

Account information

TallyMap uses Sign in with Apple as its only sign-in method. When you sign in, Apple gives us a stable, app-specific user identifier and, if you choose to share it, your email address (or an Apple "Hide My Email" relay address). We use these to create and authenticate your account. We never see your Apple ID password. Your display name and handle inside the app are derived from your email unless you change them.

Bank transaction data (via Plaid)

If you connect a bank or card, our data provider Plaid Inc. retrieves your transactions and delivers them to the app. For each transaction we receive: the transaction description and merchant name, the amount, the date, Plaid's spending category, the merchant's location (latitude and longitude, when the merchant record includes it), and the name of the institution you connected. We request Plaid's Transactions product only, for US institutions only.

Plaid handles the actual login to your bank. Your bank credentials are entered in Plaid's interface and are never sent to or stored by FinShark.

Data the app computes

On your phone, TallyMap turns transactions into "places" (a merchant at a location), tally strokes, spending totals by place and period, skip streaks, stickers and badges, and the week and month summaries shown in widgets. Neighborhood labels ("Mission District") are produced by sending merchant coordinates to Apple's reverse-geocoding service. All of this is derived data about your spending and is stored on your device.

Things you enter

Anything you type or choose in the app: check-ins, skips, "not me" flags on transactions, filters, profile changes, and, when friend features are available, the dares, taunts, and messages you send to friends.

Technical data

When the app talks to our backend (hosted on Supabase) the request carries your IP address, a timestamp, and your session token. Supabase keeps standard server logs for a short period for security and debugging. We don't build profiles from these logs.

Notifications

If you allow notifications, the app schedules reminders on your device (check-in nudges, the Sunday weekly digest). If we add server-sent push notifications (for example, when a friend dares you), Apple's push service will hold a device token that lets us reach your phone. You can turn notifications off anytime in iOS Settings.

3.WHAT WE DON'T COLLECT

  • Your phone's location. TallyMap never requests Location Services permission. Map positions come from merchant data in your transactions, not from where your phone is.
  • Your contacts, photos, camera, microphone, or calendar. The app does not request these permissions.
  • Bank credentials or account numbers. Those stay with Plaid and your bank.
  • Analytics or advertising identifiers. The app contains no analytics, crash-reporting, or advertising SDKs, and does not use the IDFA or track you across other companies' apps and websites. Because we don't track, the app does not show the App Tracking Transparency prompt.

If we later add a privacy-respecting crash reporter or product analytics, we will limit it to app-level events (screens, errors) with no transaction contents, update this policy, and update the App Store privacy label before that version ships.

4.WHERE YOUR DATA LIVES

On your iPhone

Your transactions, places, tally, stickers, and caches are stored in an on-device database protected with iOS Data Protection (the "complete" file-protection class, so the data is encrypted whenever your phone is locked). A small summary (this month's total, stroke counts, streak, and the week's day-by-day state) is shared with the TallyMap widgets through an app group container on the same device. If you use iCloud or encrypted device backups, your device's copy of this data is included in those backups under Apple's terms.

On our backend

Our backend runs on Supabase in the United States. We store there only: your account record (Apple identifier, email if shared, sign-in timestamps), and, for each connected bank, the institution name, a sync cursor that tells Plaid where we left off, and the Plaid access token that lets our server request your transactions. Access tokens are encrypted at rest with a key held only by our server functions, and the table that holds them cannot be read by the app or by any user. Transactions pass through our server to your phone and are not stored there.

5.HOW WE USE IT

We use your data to provide the Service: to sign you in, to fetch your transactions from Plaid and show them as strokes on your map, to compute tallies, streaks, stickers, and digests, to send the notifications you've enabled, to run friend features you opt into, to answer support requests, to keep the Service secure, and to comply with law. We do not use your data for advertising, to build marketing profiles, or to train machine-learning models.

Where a law requires a legal basis, we rely on the performance of our agreement with you (providing the app), our legitimate interests in security and improving the app, and your consent where we ask for it (for example, notifications and bank connections, which you can withdraw at any time).

6.WHO WE SHARE IT WITH

We share data only with the service providers needed to run TallyMap, only as needed to provide it:

ProviderWhat they handleTheir policy
Plaid Inc.Connects to your bank and provides transaction data. When you link an account you also agree to Plaid's end-user terms; Plaid acts as an independent controller for the data it collects from your bank.plaid.com/legal
SupabaseHosts our authentication, database, and server functions.supabase.com/privacy
AppleSign in with Apple; reverse geocoding of merchant coordinates; push notifications; App Store purchases.apple.com/legal/privacy
VercelHosts this website (tallymap.app).vercel.com/legal/privacy-policy

We may also disclose data if required by law, subpoena, or court order; to protect the rights, safety, or property of FinShark, our users, or the public; or as part of a merger, acquisition, or sale of assets, in which case this policy continues to apply to your data and we will notify you of any change in ownership.

We do not sell your personal information and we do not share it for cross-context behavioral advertising, as those terms are defined in the California Consumer Privacy Act and similar state laws. We have not done so in the past twelve months.

7.FRIENDS & DARES

TallyMap's social features (friends, leaderboards, dares, taunts, and the inbox) are being rolled out. When they are available and you choose to use them:

  • Friends you connect with can see your display name, handle, tally stroke counts, skip streaks, stickers, and dare status.
  • For a dare, the friend you dare can see the spot the dare is about (for example, a coffee shop) and whether you kept or broke it.
  • Friends never see dollar amounts, your transaction list, your bank or card details, or your full map.
  • Messages you send (taunts, dare text) are visible to their recipients.

Friend features are opt-in: nothing is shared with anyone until you add a friend or accept a dare. You can remove a friend or leave a dare at any time in the app.

8.DELETING YOUR DATA

  • Sign out (Profile → Account → Sign out) wipes all financial data from your device: transactions, derived places, the connected-bank list, and location caches. Your account and bank connections remain so you can sign back in.
  • Disconnect a bank to stop syncing that institution. You can also revoke TallyMap's access at any time from Plaid's portal at my.plaid.com.
  • Delete your account (Profile → Account → Delete account) permanently removes your account record and stored bank access tokens from our backend, revokes every bank connection at Plaid, and erases the app's data from your device. This cannot be undone.

You don't need to email us to do any of the above, but you can (hello@tallymap.app) and we'll help.

9.RETENTION

Transactions and derived data live on your device until you sign out, delete your account, or delete the app. Backend account records and encrypted access tokens are kept until you delete your account. Supabase's server logs and database backups are retained for a limited period (days to a few weeks, depending on the plan) and then overwritten; deleted accounts disappear from backups on that schedule. Support emails are kept as long as needed to resolve your request.

10.SECURITY

We designed TallyMap so that the most sensitive data never reaches us. Bank credentials stay with Plaid. Transactions stay on your phone under iOS Data Protection. Plaid access tokens are encrypted at rest on our server, readable only by our server functions, and held in a table with no client access. All traffic between the app, our backend, and Plaid uses TLS. Your session is protected by Apple's sign-in and expires automatically. We ran a security review of the backend and the app's data lifecycle before beta and fixed everything it found.

No system is perfectly secure. If we learn of a breach that affects your data, we will notify you and any regulators as required by law.

11.YOUR RIGHTS

Depending on where you live (including California, Colorado, Connecticut, Virginia, Utah, and other US states with privacy laws, and the EU/UK if you use the app there), you may have the right to access, correct, delete, or receive a copy of your personal data, to opt out of sales or targeted advertising (we do neither), and to not be discriminated against for exercising these rights.

Most of these you can exercise yourself: everything TallyMap knows about your spending is on your phone, and account deletion is one tap away. For anything else, email hello@tallymap.app from the address on your account and we'll respond within the time required by your local law (generally 45 days). If we deny a request, you can appeal by replying to our response. You may also authorize an agent to make a request for you; we'll ask for proof of that authorization.

If you're in the EU or UK you may lodge a complaint with your local data protection authority. Data we hold is processed in the United States; by using the Service you understand that your data is transferred there.

12.CHILDREN

TallyMap is for people 13 and older. We do not knowingly collect personal information from children under 13. If you believe a child under 13 has created an account, contact us and we'll delete it. Users under 18 should use the app with a parent or guardian's permission, and can only connect financial accounts they are authorized to access.

13.THIS WEBSITE

tallymap.app is a static site hosted on Vercel. It sets no cookies, has no accounts, and runs no analytics. Vercel keeps standard access logs (IP address, browser, pages requested) for security and capacity purposes. The site loads fonts from Google Fonts, which means Google receives your IP address when the font files are requested; see Google's privacy policy.

14.CHANGES

We'll update this policy as the app evolves (for example, when friend features, subscriptions, or push notifications launch). We'll post the new version here with a new effective date, and for material changes we'll tell you in the app before they take effect. Continuing to use TallyMap after a change means you accept the updated policy.

15.CONTACT

Questions, requests, or complaints about privacy: hello@tallymap.app. Please include "Privacy" in the subject line so we can route it quickly.

FinShark · TallyMap · New York, USA

TALLYMAP
privacytermssupport
© 2026 FinShark · made in the city