Privacy

What is collected, why, and what the service has no ability to read.

Draft — Not Yet Reviewed By Counsel. This page describes how the product is built today. It can change before it is final.

The Short Version

Your tally names, numbers, notes, emoji, folder names, display name and themes are encrypted on your device before they are synchronized. The service stores them as ciphertext and holds no key that opens them. It does keep a small amount of account and routing information, listed below, because it cannot work without it.

Seen and Not Seen

What the Service Can See

  • Your account email address, kept in a protected form so sign-in mail can reach you.
  • Which sign-in method you used, and a reference from that provider.
  • Routing details: random identifiers for your devices, spaces and tallies, the order events arrived in, and when.
  • Sizes and counts: how much encrypted data you store and how many requests you make.
  • Usage counts with no account attached, and only if you turn them on in the app: for example that a tally was created, or which built-in theme was picked.
  • How many accounts were created and how many sign-ins succeeded each day, as daily numbers with no account attached. The service counts these itself, whatever you choose in the app.

What It Cannot Read

  • Tally names and folder names.
  • Values: every count, increment and total.
  • Notes and descriptions.
  • The emoji you pick.
  • Which theme your account uses, and the names and colors of themes you make.

Account Information

Routing Information

To store and deliver ciphertext, the service keeps random identifiers for spaces, folders and tallies, which account and device wrote each event, sequence numbers, key versions, timestamps, and the size of what you store. From this it can tell that a tally exists and how often it changes. It cannot tell what the tally is called or what its count is.

Usage Counts

Product analytics are optional and off unless you turn them on in the app, under Settings, Privacy. The choice is kept in that browser, so it is made again on each device. When it is on, the app sends a short, fixed list of events: that a tally was created and of which kind, roughly how many entries synced at once, the name of a built-in theme you picked (or just the word custom), that an import finished (the kind of file, and ranges for how many rows it had and how long it took), and an error code when something fails. These carry a platform and an app version. They carry no account, session or device identifier, no free text, and no tally content. Anything not on the fixed list is refused.

That switch does not turn off what the service needs to run and protect itself: sign-in records, limits on repeated requests, and content-free operational logs.

What the Service Counts Regardless

Two things are counted by the service itself, at the moment they happen on the server, and do not depend on that switch: that an account was created, and that a sign-in succeeded. Each is stored as the day, the platform (web) and the method: an email link or a sign-in provider, without saying which provider. Nothing else is stored with it. There is no account, session or device identifier, no email address, no network address and no provider identifier, so a count cannot be traced back to a person. They tell the people who run the service how many sign-ups and sign-ins there were in a day, with no account attached, and nothing more. They are kept as long as other usage counts.

On Your Device

The app keeps an encrypted copy of your vault in the browser's storage so it works without a connection. Beside it, in readable form, it keeps which theme to draw before you unlock (an identifier, never a name or a color you chose) and whether you turned product analytics on. While an import is unfinished, an encrypted note of where it stood is kept there as well and removed when the import ends; the file you chose is never kept. Signing out removes this account's data from that browser.

What Is Never Collected

This Website

This site is plain pages. It sets no cookies, runs no scripts and loads nothing from other companies. Its access log is set up to leave out visitor addresses. If you use the contact form, your message and the reply address you choose to give are sent to the product's own support mailbox and deleted once handled.

How Long Things Are Kept

These are the intended periods. The cleanup jobs that enforce some of them are still being put in place, which is one reason this page is a draft.

Selling and Sharing

Your data is not sold, rented, or handed to advertisers or data brokers. Sign-in providers learn that you signed in to this product, as they do with any app. Mail is delivered through the product domain's own mail service.

Your Choices

In the app you can revoke a device, turn product analytics on or off, and sign out, which removes this account's data from that browser. You can also take your tallies out as plain files or as an encrypted backup, and replace your recovery key. A plain export is not protected by your vault once it is written. Deleting an account from inside the app is planned and not available yet; until it is, ask through the contact form and choose Privacy.