Privacy: what Tally reads, stores and shows
Tally is a student-built sales-insights tool for small restaurants and cafes. This page describes exactly what the app does today. Last updated October 2, 2026.
If you just upload a file
- Your sales file is read and saved only in this browser on this device. It is not uploaded to Tally.
- Customer columns (phone, email, loyalty ID, name), if you choose one, are scrambled on your device before anything is saved.
- No account, no analytics, no ads, no tracking.
- Optional weather (off by default) sends an approximate location and date ranges to the free Open-Meteo service. Never your sales.
If you connect Square
Connecting Square also signs you in to a Tally account. Tally asks Square for read-only access: your business name and locations, and your completed orders. It can never charge, refund or change anything in Square.
Stored on Tally's server (a Cloudflare database):
- Your Square merchant ID and business name.
- Square's access keys for your account, encrypted.
- When you last synced, and your sign-in sessions (stored scrambled, so a copy of the database can't be used to sign in as you).
Your sales themselves pass through to your browser and are saved only on your device, the same as an uploaded file.
If you choose "Save this report to my account"
Saving is optional and off until you press the button. Each saved report contains only a summary:
- The date range, total sales, number of orders and average order.
- Average sales per weekday and per hour.
- Your top 10 items (name, number sold, sales).
- The insight sentences shown on your dashboard.
It never contains individual sales, receipts, customer details or card information.
Anonymous step counting
To learn where Tally is confusing, it can count steps, such as "opened Tally", "chose a file", "file not recognized: dates", "connected Square" or "saw a report". This only runs once it has been switched on for the site; there's no record from before that.
- Each step is stored with a fixed name, an optional fixed reason code, the time, and a random ID made by your browser. The ID isn't a fingerprint, and Delete all my data replaces it.
- It never includes your sales, item names, amounts, file contents, business name, IP address or browser details.
- Only Tally's admin sees the totals, as counts on a private page.
- If your browser sends Global Privacy Control or Do Not Track, nothing is counted.
Who can see it
- You, from any browser where you're signed in with Square.
- Tally has no screen or feature that lets anyone else, including Tally's admin, read your saved reports or your Square data.
- To be fully honest: Tally's operator runs the Cloudflare account where this database lives and could technically open it. We don't, and Square keys are stored encrypted. If that's not acceptable to you, keep using Tally without connecting Square or saving reports. Everything else works the same.
Deleting your data
- Delete one saved report, or Delete all my saved reports, from your account card on the My Data page.
- Sign out ends the session in that browser. Your saved reports stay.
- Disconnect & delete account revokes Tally's Square access and deletes your stored keys, sessions, saved reports and account.
- You can also remove Tally from the Apps section of your Square Dashboard at any time.
- Sales saved in this browser are deleted with Delete all my data on the My Data page.