Privacy

Last updated: August 11, 2026

Tally (tally.markets) is operated by Prosperity Labs, LLC, a limited liability company registered in the United States, which is the controller of the data described below. Reach us any time at support@tally.markets.

1.What we collect

  • Account — your email address and an identifier from our authentication provider. Passwords are never stored by us; sign-in is handled by Clerk.
  • What you write — your theses, criteria, positions, fills, notes, and reviews. This is the product; it's yours.
  • Venue connections — if you connect a venue, the wallet address (not a secret) and a read-only session key, which is encrypted at rest with AES-256-GCM before it touches the database. It is used only to read your positions, never to trade.
  • Broker connections — if you connect a brokerage account, you sign in at your broker inside SnapTrade's portal; your broker credentials never touch Tally. What we store is an access secret issued by SnapTrade (encrypted at rest with AES-256-GCM), plus the read-only data we sync through it: institution and account names, balances, positions, and transaction history. It is used to reconcile your journal against what actually happened at the broker — never to trade.
  • Connected AI assistants — if you add the Tally connector in Claude or ChatGPT, your assistant reads and writes your journal through an OAuth grant you approve and can revoke. The assistant acts on your behalf under your own account with that provider; we don't send your journal to Anthropic or OpenAI ourselves.
  • Alerts — the email address you choose for watcher alerts, which may differ from your account email. Until you choose one, alerts go to your account email, because an alert nobody receives is the failure this product exists to prevent. Turn them off or redirect them at any time in settings.
  • Billing — your plan and the customer/subscription identifiers issued by Stripe. We never see or store your card details; payment data goes directly to Stripe.

2.What we don't collect

No advertising trackers, no third-party analytics scripts, no cross-site profiling. We don't sell or rent personal data to anyone, and we don't use your journal content to advertise to you. The only cookies we set are the ones the product needs: your session, and a referral code if you arrived through someone's link.

3.Your journal is private by default

Theses, positions, and watcher alerts are scoped to your account — other users cannot see them. The one exception is deliberate: a receipt page you share is public by design, and shows only the process record (title, statement, dates, criteria counts, status, and — once closed — the return as a multiple of your risk budget). Receipts never include dollar amounts, position sizes, wallet addresses, or venue details.

4.Who processes your data

We use a small number of subprocessors:

  • Clerk — authentication and account management
  • Neon — the Postgres database
  • Vercel — web hosting
  • Fly.io — the background worker that runs watchers and venue syncs
  • SnapTrade — read-only brokerage connectivity (account data and transaction history; never order placement)
  • Stripe — payments and subscription billing
  • Resend — alert and notification email

These providers operate in several countries, so your data may be processed outside where you live. Market and news data we read (for example public options data and news-volume indices) is fetched without sending your personal information.

5.Security

Traffic is encrypted in transit. Venue session keys and SnapTrade access secrets are encrypted at rest with AES-256-GCM using a key held outside the database, and they are decrypted only to read your account data. Broker connections are established read-only at the API level — Tally has no ability to place, modify, or cancel orders, by architecture and by policy. No system is perfectly secure; don't give any application more permission than it needs.

6.Your data, your call

Email support@tally.markets from your account address to get a copy of your data, correct it, or have your account and its contents deleted. Deletion removes your journal, connections, and preferences; we keep the minimum billing records we're required to retain for tax and accounting purposes. Depending on where you live you may have additional statutory rights (for example under GDPR or UK GDPR) — those apply, and the same address reaches us.

You can disconnect a broker or venue at any time from your dashboard — disconnecting a broker revokes our access and queues deletion of the connection at SnapTrade. The AI connector's access can be revoked from your Tally account settings or by removing the connector in Claude or ChatGPT. Alert emails turn off from the dashboard too.

7.Retention and changes

We keep your journal for as long as your account exists — closed and abandoned theses included, because the record is the point. If we materially change this policy we'll post the update here with a new date. Questions: support@tally.markets.