Privacy Policy
Last updated: August 17, 2026
FairTally respects your privacy. This policy explains what data we collect, why we collect it, how long we keep it, and what rights you have.
1. Who we are
FairTally is a trade name of Venture Melody LLC, which operates the FairTally website and mobile/web app. You can create an account and manage shared expenses with others through these services.
For data questions, contact us at hello@fairtally.com.
2. Information we collect
Information you give us
- Name. When you create an account, we collect a display name so other users can identify you in shared groups and expenses.
- Email address. Used to create and authenticate your account, send transactional messages (e.g., expense invites, password reset), and communicate with you about the service.
- Financial data (expenses and settlements). When you use the app, we store the expense records, amounts, splits, and settlement transactions you create. This data is the core of the service and is tied to your account.
- Payment information. Web subscriptions are processed by Stripe; iOS and Android subscriptions are processed by Apple (App Store) or Google (Google Play). We never see or store your card details. For native subscribers we store a verified entitlement and an opaque transaction identifier so restore-purchase requests can be matched to your account.
Information collected automatically
- IP address in audit logs. We record your IP address for security-relevant account actions (sign-in, password/email changes, deletion, subscription events, and similar). IP is anonymized after 90 days and the entry is deleted after 365 days.
- Subscription verification (iOS/Android). If you subscribe in the app, we share an opaque household ID and your App Store/Play Store receipt with RevenueCat to verify the purchase and track entitlements. RevenueCat does not receive your name or email.
- Product analytics (web, iOS, and Android apps). If you choose “Allow analytics,” PostHog receives optional client-side events about screens viewed, first-value prompts, paywall and checkout steps, and purchase restoration. Independently, our servers send a limited set of account and household setup, expense-count milestone, settlement, and subscription lifecycle events to measure activation, reliability, and subscription flows. Events may include platform, app version, billing provider, billing interval, and non-sensitive status or reason codes. We do not send names, email addresses, household names, join codes, expense descriptions, amounts, categories, receipts, transaction IDs, or provider error messages to PostHog.
- Analytics identifiers. If you allow client-side analytics before sign-in, PostHog assigns a random identifier stored on your device. After sign-in, we use opaque identifiers derived from our internal user and household IDs so we can measure activation and retention without sending direct contact information. Server-side lifecycle events use the same opaque account or household identifiers. PostHog is configured to discard client IP addresses after limited processing for functions such as geolocation enrichment and bot detection.
- Marketing site (fairtally.com). Our public marketing pages load Google Fonts (Google receives your IP). If you choose “Accept” on the landing page, Google Analytics collects information such as page views, approximate location, device and browser details, referring pages, scrolls, and outbound-link clicks. Google Analytics may set first-party cookies beginning with
_ga. We do not send your name, email address, or financial data to Google Analytics. - Analytics preference. We save your analytics choice in browser or device preference storage under
fairtally_analytics_consent. If you decline on the marketing site, the Google Analytics tag is not loaded. If you decline in the app, optional client-side PostHog analytics is not initialized. You can change the app preference at any time under Profile → Privacy & Security. We do not use the Meta Pixel or other advertising trackers on the marketing site.
The web app uses an httpOnly session cookie for sign-in. When client-side analytics is allowed, PostHog stores a random analytics identifier in local storage on web and device storage on Capacitor app surfaces. We disable PostHog autocapture, automatic page views, heatmaps, Web Vitals collection, advertising features, and session replay, and we honor browser Do Not Track signals.
3. Legal basis for processing
We process your data under the following legal bases:
- Contract performance. We process your name, email, and financial data because it is necessary to provide the service you signed up for, including account creation, expense tracking, and settlements.
- Consent. We use Google Analytics on the landing page only when you choose “Accept,” and we use optional client-side PostHog analytics in the app only when you choose “Allow analytics.” You may withdraw landing-page consent through the “Cookie settings” link in the footer and app analytics consent under Profile → Privacy & Security.
- Legitimate interests. We log IP addresses in audit logs to detect and prevent fraud and unauthorized account access. Our servers also send limited lifecycle analytics to understand activation, improve reliability, and measure subscription flows. We minimize these events and exclude financial and free-form content. Optional client-side PostHog analytics is not processed under this basis and remains disabled unless you consent.
- Legal obligation. We may retain or disclose data where required by applicable law.
4. Third-party providers
We do not sell your information. We share data only with the providers below, all US-based:
- Stripe: web subscription payments.
- Apple and Google: App Store and Play Store billing for iOS/Android subscriptions.
- RevenueCat: verifies native subscriptions and tracks entitlements.
- Resend: transactional email delivery.
- Railway: application and database hosting.
- Cloudflare: DNS, CDN, and DDoS protection.
- PostHog: privacy-limited product analytics for the web, iOS, and Android apps, hosted in PostHog's US Cloud.
- Google Fonts (marketing site only): web font delivery.
- Google Analytics (landing page only, with consent): website traffic and interaction measurement.
We may also disclose information if required by law.
5. Data retention
- Account data and your expense/settlement records: Kept until you delete your account or the household is deleted.
- Audit log IP addresses: Anonymized after 90 days; the entry is deleted after 365 days.
- Subscription identifiers: Kept for the life of the household so restore-purchase requests can be matched to your account.
- PostHog product analytics: PostHog may retain events for up to 84 months (7 years) under our current US Cloud project settings. The random local analytics identifier remains on the device until app/site data is cleared, the analytics identity is reset, or you opt out.
- Google Analytics marketing-site data: Retained according to the Google Analytics data-retention settings. Your browser keeps your consent preference until you change it or clear your site data.
6. Account and data deletion
You can delete your account at any time from the app settings, or by emailing hello@fairtally.com. Deletion is permanent. If you were the sole member of a household, all your expenses and settlements are deleted with you. If others remained in the household, the records you created are kept for them but your name is replaced with "Former Member" so they cannot be linked back to you.
7. Your rights
You can access, export, correct, or delete your data directly in the app, or by emailing hello@fairtally.com. You may also request deletion of product-analytics data associated with your opaque account identifier. You can change or withdraw your landing-page cookie choice through the “Cookie settings” link in the footer and your app analytics choice under Profile → Privacy & Security. Our emails are transactional and don't include an unsubscribe link; to stop receiving them, delete your account.
8. App Store and Google Play labels
The FairTally app collects Contact Info (email), Financial Info (expenses, settlements, store receipts), Identifiers (user, household, and randomly generated analytics IDs), and Usage Data (product interactions and IP in security audit logs). Optional client-side product-interaction events are used for analytics only after consent; limited server-side lifecycle events are used for analytics under our legitimate interests. The remaining data is used for app functionality, account security, and subscription management. Analytics becomes linked to an opaque account identifier after sign-in. FairTally does not use this data to track you across other companies' apps or websites, does not use it for advertising, and does not record sessions.
9. Security and breach notification
We use HTTPS for data in transit, store passwords as salted hashes, and protect production access with multi-factor authentication. In the event of a personal data breach likely to risk your rights, we will notify affected users without undue delay and the relevant supervisory authority within 72 hours, as required by GDPR Articles 33 and 34.
10. Children
The service is not for anyone under 18. We do not knowingly collect data from minors. If you believe we have, contact us and we will delete it promptly.
11. International transfers
Our providers are US-based. For users in the EEA, UK, or Switzerland, we rely on the EU-US Data Privacy Framework where a processor is certified, and on Standard Contractual Clauses otherwise. You may also lodge a complaint with your local data protection authority.
12. Changes
We may update this policy from time to time. Material changes will be communicated by email or a notice on the site. The "Last updated" date at the top always reflects the current version.
13. Contact
For privacy questions, data requests (access, export, deletion, rectification), or to report a concern, email hello@fairtally.com. We aim to respond within 5 business days.