Privacy Policy
Last updated September 20, 2026
The short version
Tallyhook reads AI coding-agent session logs on your machine (Claude Code, Codex) and uploads metadata only — token counts, timing, repo/branch, developer identity, and (optionally) the first 160 characters of your first prompt. It never uploads transcripts, code, diffs, tool output, or environment variables. You can disable even the prompt snippet with a one-line config change. The full technical breakdown is on the homepage, and the collector itself is open source (MIT) and one readable file — read it before you run it.
1. What we collect
Account data. If you sign in with GitHub, we read your GitHub profile and primary email to create your account. We don't request or store any other GitHub data or permissions.
Session metadata, uploaded by the collector you install: tool and version, start/end time, git remote and branch, which repositories the edited files belong to, developer identity (from your local git config), token counts by model (including cache reads/writes), turn count, tool-call counts, file paths edited, and — unless you set "privacy": true in ~/.tallyhook/config.json — the first 160 characters of your first prompt in each session.
Never collected: transcripts, any prompt or response text beyond that one 160-character snippet, code, diffs, tool output, or environment variables/secrets.
Billing data. Payment card details are handled entirely by Stripe; we never see or store your card number. We do store your Stripe customer and subscription IDs to know your plan.
Usage data. Standard server logs (IP address, request timing) for security and debugging, kept only as long as needed for that purpose.
Site analytics. We log basic pageview data for our own public pages (page path, referring site, and the marketing campaign that brought you here, if any) so we can tell what's working. This runs entirely on our own server — no cookies, no client-side script, no third-party analytics service. We compute a one-way, same-day-only hash of your IP address and browser to get an approximate unique-visitor count; that hash rotates daily and cannot be reversed back to your IP or used to track you across days or sites. If you create an account, we use the same same-day hash once to note which source brought you (for example a campaign tag or a referring site) and store that label on your account. Inside the product we record a few plain events against your workspace, such as the first sync, a CSV export or a started checkout, to understand where people get stuck.
Feature requests. If you ask to be told when something unbuilt ships (the form at the bottom of the features page), we store that email address and which feature you asked about, and nothing else. It is used to tell you when that feature ships and to count how many people want it. It is not a mailing list, it is never sold or shared, and you can have the entry deleted by emailing us.
The demo. The live demo sets one short-lived cookie that marks your browser as viewing sample data. It holds no identifier.
2. How we use it
To run the product: attribute sessions to the right client, compute costs, generate invoices and exports, and let your team see its own usage. To bill you, via Stripe. To send you service emails about your own account: a welcome note, alerts and budget notices you switched on, and a heads-up before and after your trial ends. To respond when you email support. We do not sell your data, and we do not use session content to train any model.
3. Who can see it
Everyone who is a member of your workspace can see all of that workspace's clients, sessions, and costs — this is a deliberate design choice for a small-team tool, not a bug; it's stated plainly in the product itself. Data from one workspace is never visible to another workspace, enforced at the database level, not just in the interface.
4. Where it's stored
In a single database on our hosting provider (Fly.io), in one region. Backups are operational (protecting against data loss), not a separate long-term archive.
5. Third parties
We use Stripe for payment processing and GitHub for sign-in. Each has its own privacy policy governing the data they process on our behalf. We don't share your data with any other third party.
6. Your choices
You can turn off prompt-snippet collection at any time ("privacy": true) or uninstall the collector entirely (npx tallyhook uninstall).
Taking your data with you. Settings → Your data has a one-click JSON export of everything your workspace holds: every session with its full token breakdown, your clients or teams, repo mappings, developers, settings and activity log. It is never gated on your plan, including after a trial ends, because the moment you stop paying is exactly when you need your own data out. The only thing withheld is collector token secrets, which we store as a hash and cannot reproduce.
Deleting it. The same page deletes the whole workspace — every session, client, mapping, token and share link — immediately and permanently, cancelling any Stripe subscription first. We keep no copy for you to restore from afterwards, so export first if you want it. If you would rather we did it, or you want your user account removed as well, email support@tallyhook.dev.
7. Changes to this policy
If this policy changes materially, we'll update the date above.
8. Contact
This policy describes Tallyhook's actual data practices as of the date above. It has not been reviewed by outside counsel; treat it as a solid working draft rather than a substitute for legal advice specific to your jurisdiction or business.