Privacy Policy
Last updated: September 9, 2026
Who we are
Tallymeter is operated by MB Nexus Consulting, a company registered in Lithuania (EU), which acts as the data controller for your account data. Contact: [email protected].
What we collect
- Account data : your name, email address and password (hashed).
- Product data you create : time entries and their descriptions, projects, invoices, and the business details you enter in Settings (company details, client details, bank details : bank details are encrypted at rest).
- Integration data : if you connect Jira, your Jira server URL, Atlassian account email, API token (encrypted at rest) and project key; worklog data is exchanged with your Jira instance only when you trigger a sync.
- Billing data : subscription status and invoices, processed by Stripe. We never see or store your card number.
- Usage data : anonymous, cookieless page-view counts on our marketing pages (no visitor profiles, no advertising trackers), and error reports (Sentry) that may include your account id when something breaks.
First-party usage measurement
We operate Pulse, a private analytics service on our servers in Germany. On public pages it records page paths, referring domains, campaign tags, coarse country and device information, and visible page time. It does not use analytics cookies. A daily, site-specific hash derived from the IP address and browser information estimates visitor counts; raw IP addresses are not stored in the analytics database. Standard security logs are separate.
Pulse also receives signup, time-entry and subscription-creation events with timestamps and pseudonymous account identifiers. It does not receive entry descriptions, invoices, customer emails or payment details. Website visitors are not linked to product accounts or tracked across projects. Detailed observations are retained for up to 180 days, and backups for up to 14 days. Account-linked analytics are removed after account deletion at the next successful source sync.
Product conversion measurement
We also count visits to the homepage, audience pages, demo and registration, and actions such as viewing a sample invoice or completing signup. This uses the existing application session cookie and a daily pseudonymous session hash. We store only a fixed action name, a coarse entry-source category and a timestamp. We do not store an account identifier, IP address, invoice content or form values with these observations, or join them to product accounts. These observations are deleted after 180 days. Aggregate activation and subscription counts are calculated separately from our product records.
Where it lives
Application data is hosted on Hetzner Online GmbH servers in Germany (EU). Traffic is proxied through Cloudflare. Backups stay within the EU.
Subprocessors
- Hetzner Online GmbH (DE) : hosting
- Cloudflare, Inc. (US) : CDN, TLS and DDoS protection
- Stripe, Inc. (US) : subscription billing
- Resend (US) : transactional email (verification, password reset)
- Functional Software, Inc. dba Sentry (US) : error monitoring
- Atlassian Pty Ltd : only if you install the Tallymeter for Jira app: Atlassian's Forge platform stores the OAuth tokens that connect your Jira user to your Tallymeter account
The Jira app
The Tallymeter for Jira app runs on Atlassian Forge. It sends the issue key and issue summary of tickets you interact with to tallymeter.com to start timers and show tracked totals. It reads nothing else from your Jira site, and connects only the Jira users who explicitly authorize it through the OAuth consent screen. Revoke access anytime from Atlassian's Connected Apps screen or by deleting the "Jira panel" token in Tallymeter → Settings → API tokens.
Retention & your rights
Your data stays as long as your account exists : when a plan lapses, data is never deleted, only access is paused. You can export your time entries (CSV) at any time. To delete your account and all its data, email us; deletion is completed within 30 days. Under the GDPR you have the rights of access, rectification, erasure, portability and objection : exercise any of them via [email protected].
What we don't do
- No advertising, no selling or sharing data with advertisers.
- No tracking cookies on marketing pages; the app uses only a session cookie to keep you signed in.
- No training of AI models on your data.