TrueTally
Privacy Policy
Last reviewed September 2, 2026 · Version 1.0
This owner-authored notice explains how TrueTally collects, uses, stores and deletes information when you use the application, including when you connect a financial institution through Plaid Link.
Information we collect
- — Account details needed to create your TrueTally account, such as your name and email address.
- — Financial records you enter, including accounts, transactions, receipts, paychecks and business records.
- — When you choose Plaid Link, account, balance and transaction information returned by your selected financial institution.
- — Security and operational information needed to protect the service, troubleshoot errors and maintain reliable imports.
How Plaid data is used
- — To display the accounts and balances you selected and import transactions into your ledger.
- — To categorize, deduplicate and synchronize transactions at your request or when Plaid sends an update notification.
- — To identify a connected institution and show connection status, errors and the last successful sync.
- — We do not sell your financial data or use it for third-party advertising.
Consent and your choices
We ask for your agreement before creating an account and again before collecting data through Plaid Link. Your consent records include the policy version and time of agreement. You may disconnect a bank at any time, revoke consent by contacting us, or delete your account and associated records.
Storage and protection
The managed backend encrypts database storage and backups at rest. Plaid access tokens, synchronization cursors, and retained raw Plaid account and transaction payloads receive an additional application-level AES-256-GCM encryption layer and are processed only by server-side code. Browser-facing bank status data excludes access tokens.
Retention and deletion
- — We keep your data only while your account is active, or as long as needed for a legal or tax obligation.
- — Disconnecting a bank deletes the stored connection, its encrypted access token, sync cursor and retained raw Plaid payloads, and revokes the connection with Plaid.
- — Deleting your account removes your financial records, including accounts, transactions, receipts, paychecks, invoices, bills and inventory.
- — Consent records are kept up to 24 months after deletion as proof of lawful basis. Security and error logs are kept up to 90 days. Deleted records age out of provider backups within the provider's rolling backup window.
- — Access, correction, export, deletion and consent-revocation requests can be sent to privacy@truetally.ai. We acknowledge within 5 business days and complete within 30 calendar days, consistent with applicable privacy laws such as GDPR and the CCPA/CPRA where they apply.
- — This retention and deletion policy is reviewed at least annually and whenever a new data type, integration or applicable law changes.
Service providers
TrueTally uses Plaid to connect financial institutions, managed cloud infrastructure to host the application and database, and payment and AI providers only for features you choose. Each provider receives only information needed for the requested service and is subject to its own privacy terms.
Contact
Questions or privacy requests can be sent to privacy@truetally.ai.