<!-- Template privacy policy. Placeholder legal document — have it reviewed by counsel before relying on it in production. Replace Tallied, https://withtallied.com, and support@localhost are substituted automatically when this page is served; everything else is yours to edit. -->

Privacy Policy

Effective September 2026

This policy explains what Tallied collects, why, and how you can control or delete it. Tallied is a time-tracking and invoicing tool you use from an AI assistant (like Claude or ChatGPT) or from the web app at https://withtallied.com/app.

What we collect

What we do not collect

How AI assistants access your data

An assistant can only read or change your Tallied data after you connect it through OAuth and approve the scopes it's requesting. In plain language, those scopes are:

Access tokens expire after 1 hour. Refresh tokens last 30 days and rotate every time they're used, so a stolen refresh token stops working the moment the real one is used again. You can revoke access at any time by removing the connector from Claude, ChatGPT, or whichever app you connected — this immediately invalidates its tokens.

Subprocessors

We use a small number of service providers to run Tallied:

We don't sell your data or share it with anyone else for advertising.

Retention and deletion

We keep your data for as long as your account is active. To delete your account and workspace, email support@localhost. Deleting your workspace removes your time entries, clients, projects, invoices, and audit log; it does not retroactively delete records Stripe or the email provider already hold in their own systems as required by their own retention rules (e.g. completed payment records).

Security

Children

Tallied is a business tool and is not directed at, or knowingly used to collect information from, children under 13.

Changes to this policy

We'll update the effective date above when this policy changes. If a change is material, we'll make a reasonable effort to notify account holders by email.

Contact

Questions about this policy or your data: support@localhost.