Tallyhand by Belweave · Effective October 2, 2026
Privacy policy
This policy explains how Belweave handles information for tallyhand.xyz and the Tallyhand plugin. We do not sell personal information or use workspace records for advertising.
Who operates Tallyhand
Belweave operates the hosted service and publishes the Tallyhand plugin. Contact info@belweave.com for privacy questions and requests. This policy covers our hosted service. A separately self-hosted installation is controlled by its operator and configuration.
What we process and why
- Account information: sign-in identity, account identifiers, profile information supplied by your sign-in provider, and session information to authenticate you and protect your account.
- Workspace information: business and client contact details, projects, time entries, invoices, expenses, and other bookkeeping records or attachments you choose to store. We use these to provide the features you request.
- Agent requests: tool arguments and results necessary for operations you authorize through MCP, the API, or the CLI. Tallyhand does not require your full chat history. Your agent provider controls what it sends and how it processes the returned results.
- Operational information: hosting providers may process IP addresses, request timestamps, routes, device/network metadata, error information, and performance data to deliver, secure, and troubleshoot the service. Application MCP diagnostics record catalog counts, version, protocol, and authentication outcome; they are not intended to record credentials or workspace contents.
- Support correspondence: your email address and the information you send us, used to respond and resolve requests.
We process information to provide the service you request, maintain security and reliability, comply with applicable law, and, when required, with your consent. Do not place passwords, access tokens, payment-card details, government identifiers, or health records in agent messages, tool inputs, or support reports.
Local mode and cloud mode
Local browser mode stores workspace records in that browser. Those records are not automatically synchronized to our cloud workspace. Clearing browser storage can remove them; keep your own exports. Loading the hosted website can still involve hosting and authentication infrastructure even when you choose local mode.
Cloud mode stores workspace records with our cloud database service and associates them with your authenticated account. Self-hosting uses the storage and authentication services selected by the operator.
Who receives information
Our hosted service uses Clerk for authentication, Convex for cloud data storage and processing, and Vercel for hosting and operational infrastructure. These providers receive information necessary for their functions. Support email is processed by our email service provider.
When you connect an agent host such as ChatGPT or Codex, that provider receives tool results for your authorized operations under its own policies. Optional email delivery and payment integrations involve their configured providers, including Stripe where enabled. Payment credentials belong in the provider’s secure interface, not in the plugin.
Cloud invoices create a public-capability link by default unless you disable cloud sharing for that invoice. Anyone with a share link may access the shared record and invoice PDF until the link expires or is revoked. You can disable an invoice’s cloud link before saving or afterward. Recipients may retain copies. We may disclose information when required by law or necessary to protect rights and security; we do not sell your workspace data.
Retention and deletion
- Workspace records: retained while you use the service until you delete them, reset your workspace, or complete a verified hosted-data deletion request, subject to legal or security requirements.
- Privacy requests: we aim to fulfill verified access or deletion requests within 30 days. If more time is permitted and necessary, we will explain the reason and applicable extension.
- Support correspondence: retained for up to 12 months after the request is resolved, unless a longer period is required for a legal obligation or an active dispute.
- Operational logs: retained according to the active provider configuration. Vercel’s standard runtime-log windows range from one hour to 30 days depending on plan and observability options. Provider security and account records may have separate retention periods.
- Backups: deleted records can remain in recovery copies until the provider’s backup expiry cycle completes. A workspace reset or login deletion must not be understood as immediate erasure of every provider backup or recipient copy.
Deleting or disconnecting a sign-in or agent connection is separate from deleting cloud workspace records. Contact support for coordinated account and hosted-data deletion. We may retain the minimum information needed to record and honor a deletion request or meet a legal obligation.
Your controls and rights
You can review and update records, export supported data, revoke public links, and reset workspace data through the available controls. Revoking a token or OAuth connection removes that connection’s future access; it does not delete your workspace.
Depending on where you live, you may have rights to access, correct, delete, restrict, object to processing, withdraw consent, or receive a portable copy. Email us to exercise them. We may verify account ownership, but will not ask for your password. You may also contact your local data-protection authority. We do not discriminate against people for exercising applicable privacy rights.
Cookies, international processing, and security
Browser storage and cookies support authentication, local records, and preferences. Hosting and service providers may process information in the United States and other locations. Applicable provider agreements govern their processing; this page is not a claim of certification or a guarantee that data remains in your country.
We use account-scoped access controls and encrypted network connections for hosted access. No service can guarantee complete security. Protect your devices, connections, and backups, and contact support privately about security concerns.
Children and policy changes
Tallyhand is intended for adult business users and is not directed to children. If you believe a child has submitted personal data, contact us. We will update this page and its effective date when our practices change, and provide additional notice where required.