This Privacy Policy explains how Accrual Group Ltd ("Tallysta," "we," "us," or "our") collects, uses, shares, and protects your personal information when you use the Tallysta mobile application (the "App"), the tallysta.com website (the "Site"), and any related services (together, the "Services").
By using the Services, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree, please do not use the Services.
1. Who We Are
Tallysta is operated by Accrual Group Ltd, a company registered in England and Wales ("Tallysta," "we," "us," "our"). We are the data controller responsible for your personal information described in this Policy.
Questions, concerns, or requests regarding this Policy or your personal information can be sent to support@tallysta.com.
2. Information We Collect
2.1 Information You Provide to Us
- Account information: name, email address, and password (stored in encrypted/hashed form) when you register; or, if you sign in with Apple or Google, the name and email address provided by that provider.
- Profile information: the following fields may be stored in your user profile on our application database (Convex):
- Name — used to identify you in the App and, in shared shopping sessions, so other participants know who is who.
- Email address — used for account authentication, account recovery, Family Plan invitations, support, and essential service communications.
- Profile photo — used so other participants can recognise you in shared sessions and in-session chat. Photos are stored as files in our backend storage and referenced from your profile.
- Location — if you choose to provide it (for example city, region, country, and/or approximate coordinates), we use it to localise retailer suggestions and related compare-price features near you. We do not use profile location for continuous background tracking.
- Gender — optional. If collected, it is stored for possible future personalisation of in-app recommendations and product insights. It is not required to use core shopping, tally, collaboration, or AI features today.
- Date of birth / age — optional during onboarding if offered; used only to help personalise recommendations where enabled and which you can skip.
- Shopping content: shopping lists, list items, quantities, notes, tally/purchase records, budgets and spending records, saved recipes, and photos you capture of receipts, price tags, or products.
- Price comparison data and screenshots: when you use the price comparison feature to search for products via Google or visit retailer websites in the in-app browser, the App may capture and store the following information for items you choose to add:
- Product page URL
- Product price (if found on the page)
- Screenshot of the product page (if you choose to capture one)
- Product name and any other details you manually enter
- Collaboration content: messages you send in shared/collaborative shopping sessions, and information about sessions you create or join (e.g. session name, participant list, display names, and profile photos shown to other participants).
- Family Plan information: if you subscribe to a Family plan, the email addresses of the family members you invite (you must have their permission to share this with us).
- AI feature inputs: questions, shopping-list and tally context, budget or recipe context the App may retrieve on your behalf, and other content you submit to Tallysta AI, our AI-assisted shopping list builder, and AI recipe features (see Section 4).
- Support and feedback: information you provide when you contact support, report a bug, or submit feedback (e.g. name, email, message content, category such as feature request/bug/general feedback, and optionally attached screenshots). In-app feedback may be stored in PostHog and/or Sentry for triage.
- Purchase information: your subscription tier and status (e.g. free trial, Individual, Family, active/expired). We do not receive or store your full payment card details — these are processed directly by the Apple App Store, Google Play Store, and our subscription management provider, RevenueCat.
2.2 Information We Collect Automatically
- Device and usage information: device type, operating system and version, app version/build, language settings, platform (iOS/Android), and general usage/interaction data (e.g. features used, crash logs, performance data).
- Product analytics (PostHog): we use PostHog to measure how the App is used so we can improve product quality and prioritise features. This typically includes:
- screen views and time spent on primary screens;
- app lifecycle events (for example install, update, open, foreground/background);
- feature-usage events across shopping lists, tally, collaboration/share-and-join, compare price, recipes, spend/budget, settings, monetisation/paywall flows, and AI features;
- an internal analytics identifier linked to your account, plus limited profile details such as your email and display name when available, your Premium status, and technical properties such as app version and platform; and
- feedback or feature-request content you submit through the in-app feedback flow, when that flow is routed to PostHog.
- Diagnostics and crash reporting (Sentry): we use Sentry to monitor App stability and diagnose failures. This may include error reports, stack traces, device and app metadata, performance signals, and, where enabled, limited default personally identifiable context associated with the event (for example user identifiers or IP-related technical context provided by the SDK). Sentry may also receive optional name/email and message content when you submit feedback through a Sentry-powered feedback path. Session replay is currently disabled in our Sentry configuration. We use this data to find and fix crashes, regressions, and performance issues.
- Approximate location: derived from profile location you provide, device settings, or IP address, used to localise retailer suggestions, currency, and compare-price context where applicable. We do not continuously collect precise GPS location in the background unless a future feature specifically requests it and you grant permission.
- Cookies and similar technologies on our Site — see our Cookie Policy for details.
2.3 Camera and Photos
The App may request access to your device's camera and photo library so you can scan barcodes or price tags and attach photos to shopping items. We only access photos you explicitly choose to capture or select; we do not scan your camera roll in the background.
2.4 Information From Third Parties
If you choose to sign in using Apple or Google, those providers share your name and email address with us (as authorized by you) so we can create and secure your account.
3. How We Use Your Information
We use the information above to:
- create and manage your account and authenticate you;
- provide the core features of the Services (shopping lists, tallying, budgeting, price comparison, recipes);
- enable collaboration features, including sharing lists/sessions and in-session chat with people you invite, and showing your name and profile photo so participants can identify each other;
- localise retailer and compare-price experiences using location information you provide or that is otherwise available as described above;
- personalize your experience, including AI-generated recipe suggestions, shopping-list item suggestions, and spending insights based on your shopping activity and optional profile attributes (see Section 4);
- process subscriptions, free trials, and Family Plan membership;
- send you service communications (e.g. shopping reminders you create, account and security notices) and, where you have consented or as otherwise permitted by law, product updates or marketing;
- respond to support requests, bug reports, and feedback;
- monitor, maintain, and improve the Services, including product analytics via PostHog and crash/error diagnostics via Sentry;
- detect, investigate, and prevent fraud, abuse, or security incidents; and
- comply with legal obligations and enforce our Terms of Service.
Our legal bases for these uses (where UK/EU data protection law applies) are: performance of our contract with you (account creation, core features, subscriptions); our legitimate interests in operating, securing, and improving the Services (analytics, diagnostics, fraud and abuse prevention), balanced against your rights; your consent (for example optional profile fields, marketing communications, and non-essential cookies — see our Cookie Policy); and compliance with our legal obligations.
4. AI Features and Automated Processing
Certain features — Tallysta AI chat, the AI-assisted shopping list builder, and AI recipe suggestions — generate content using Google's Gemini generative AI models, accessed only through our secure server-side proxy. We do not ship any Gemini API key inside the mobile client. The specific Gemini model we use may change over time for quality, cost, or availability reasons; this Policy describes the category of processing rather than a specific model version.
What is AI-generated. Outputs such as recipe suggestions, cooking steps, shopping-list item suggestions, storage tips, and other assistant responses are machine-generated. They may be incomplete, outdated, or incorrect (including ingredient, allergen, nutritional, quantity, or pricing details). AI outputs are for convenience and inspiration only and are not professional medical, dietary, nutritional, or financial advice. Always verify important information yourself before relying on it.
How context is used. When you use these features, relevant context needed to answer your request may be assembled by the App and/or our backend and sent to Google's Gemini API for processing. Depending on the feature, this can include your question or prompt, active shopping-list items, tally/purchased items, budget or spend summaries, saved recipes, and limited profile context such as your display name. Tallysta AI may use a function-calling style flow so the model requests only the data categories it needs rather than always receiving your full history. Chat history for Tallysta AI is stored locally on your device for continuity within the App; only the context required for a given request is sent to the model. AI processing is subject to Google's applicable API terms. We do not use your shopping content to train third-party foundation models.
We also analyze your shopping activity — such as your most frequently purchased items and categories, typical basket size and spend, and shopping timing patterns (for example, which days or times of day you tend to shop) — to personalize suggestions and insights within the App and to help us understand aggregate shopping trends across our user base. This involves automated processing but does not produce legal or similarly significant effects concerning you, and you can continue to use the core features of the App without relying on these suggestions.
5. How We Share Your Information
We do not sell your personal information. We share information only as follows:
- Service providers (sub-processors): Firebase/Google Cloud (authentication and infrastructure), Convex (application database, real-time backend, and file storage for profile/session media), Google Gemini API (AI features, see Section 4), RevenueCat (subscription and billing management), Sentry (crash reporting, performance monitoring, and optional feedback capture — see Section 2.2), PostHog (in-app product analytics, screen/feature usage measurement, and feedback storage where enabled — see Section 2.2), Apple and Google (App Store/Play Store distribution, billing, Sign in with Apple/Google, and optional iCloud Drive/Google Drive backups you initiate), and Google Analytics (website usage analytics — see our Cookie Policy). These providers may only use your information to provide services to us and are bound by contractual confidentiality and data protection obligations.
- Other users: if you join or create a shared shopping session, participate in Family sharing, or share a list/recipe link, the content you share (and, for sessions/chat, your messages, display name, and profile photo) will be visible to the other participants in that session. Shared list/recipe links are time-limited and access is controlled by the token in the link.
- Legal and safety: we may disclose information if required by law, regulation, legal process, or governmental request, or where necessary to protect the rights, property, or safety of Tallysta, our users, or the public.
- Business transfers: if we are involved in a merger, acquisition, financing, or sale of assets, your information may be transferred as part of that transaction, subject to this Policy (or a policy at least as protective).
- Aggregated/de-identified data that has been processed such that it no longer identifies you.
6. International Data Transfers
Our service providers (including Firebase/Google Cloud, Convex, PostHog, Sentry, and Google Gemini) may store and process data outside of the United Kingdom or your country of residence, including in the United States. Where we transfer personal information internationally, we rely on appropriate safeguards recognized under UK/EU data protection law, such as Standard Contractual Clauses or the provider's adequacy/certification status.
7. Data Retention
We retain your personal information for as long as your account is active or as needed to provide the Services. Local shopping data (lists, tally records, recipes, and on-device AI chat history) is stored on your device and can be cleared at any time via Settings ("Clear Cache" or "Clear All App Data"). If you delete your account, we delete or anonymize your personal information within a reasonable period, except where we are required to retain certain records for legal, tax, fraud-prevention, or dispute-resolution purposes. Diagnostic and analytics records held by Sentry or PostHog are retained according to our configuration with those providers and our operational needs. Backups you create via iCloud Drive or Google Drive are stored in your own personal cloud storage account and are governed by Apple's/Google's respective policies, not this Policy.
8. Your Privacy Rights
8.1 United Kingdom and European Economic Area
If you are located in the UK or EEA, you have the right to: access the personal information we hold about you; request correction of inaccurate information; request erasure; restrict or object to certain processing; request portability of information you provided to us; and withdraw consent at any time where processing is based on consent. To exercise these rights, contact support@tallysta.com. You also have the right to lodge a complaint with the UK Information Commissioner's Office (ico.org.uk) or your local data protection authority.
8.2 California and Other US States
If you are a California resident, applicable law (CCPA/CPRA) gives you the right to know what personal information we collect, request deletion, correct inaccurate information, and opt out of the "sale" or "sharing" of personal information. We do not sell or share your personal information for cross-context behavioral advertising, and our website analytics only run after you affirmatively accept cookies (see our Cookie Policy). We do not collect the categories of "sensitive personal information" defined by the CPRA (such as precise geolocation, government identification numbers, or health information). To exercise these rights, contact support@tallysta.com. Residents of other US states with comprehensive privacy laws have similar rights, which we honor on request.
8.3 Other Jurisdictions
Wherever you are located, you may contact us at support@tallysta.com with any request regarding your personal information, and we will respond in accordance with applicable law.
9. Account Deletion and Data Export
You may delete your account at any time from within the App's Settings, or by emailing support@tallysta.com. You can export a copy of your shopping data at any time using the in-app Backup feature (iCloud Drive, Google Drive, or Save to Device).
10. Security
We use administrative, technical, and organizational measures designed to protect your information, including encrypted transport (HTTPS/TLS), encryption at rest for select sensitive profile fields (such as location details) in our database, account-isolated local storage on your device, server-side proxying of AI requests (so model API keys are not embedded in the client), and secure storage of authentication tokens. However, no method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
11. Children's Privacy
The Services are not directed to, and we do not knowingly collect personal information from, children under 13. If you believe a child under 13 has provided us with personal information, please contact support@tallysta.com and we will take steps to delete it.
12. Third-Party Links and Services
The App may display information about, or links to, third-party retailers and their websites for price comparison purposes. When you use the price comparison feature, you may browse third-party retailer websites within the App's in-app browser and optionally capture screenshots of product pages for your personal shopping reference. We do not claim ownership of content from third-party websites; screenshots you capture are stored for your personal use only as permitted under fair use principles. We are not responsible for the content, accuracy, or privacy practices of third-party sites. Review their privacy policies before providing any personal information.
13. Cookies (Website)
Our Site uses cookies and similar technologies as described in our Cookie Policy.
14. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you via the App or Site, or by other reasonable means, before the changes take effect. The "Last updated" date at the top of this Policy indicates when it was last revised.
15. Contact Us
Accrual Group Ltd
Email: support@tallysta.com