Privacy
What we collect, where it lives, and what we never do.
Last updated
In short
Using Tacca requires an account. The phone does the maths, so the app works without a connection too, but what you write is copied to our server as soon as there is one: that is what keeps your groups safe even if the phone breaks, and what carries them to the people you share them with.
We collect your email address so you can log in, and the data of your groups in order to sync them. No ads, no profiling, no selling data — this is not a statement of good intentions, it is that no code exists to do it.
Who processes your data
The data controller is IPGS ENERGY SRL, registered at Via Ugo Ojetti 7, 20151 Milano, Italia, VAT number 07006920966.
For any question, or to exercise your rights, write to privacy@usetacca.com. We answer within thirty days, as the European Regulation requires.
Before you sign in, and the example group
Until you sign in — while you are looking at the example group, or before you choose how to start — everything you write stays in a database inside the app, on your phone, and nothing reaches us. The example group in particular never leaves this phone: it is created already marked as sent, and is never sent to anyone.
One thing is true either way, with or without an account: there is no telemetry, no analytics service, no crash reporter shipping data elsewhere. The only things that leave are the ones listed below, and they leave because that is what brings them back to you and to the people in your groups.
What we collect
The account serves three purposes: keeping your groups safe beyond this phone, finding them again on another one, and sharing them with other people. To do that we collect:
- Your email address, to sign you in. We will never send you marketing: it is used only for login codes.
- The data of all your groups: participant names, expense descriptions, amounts, dates, categories, who paid and who owes.
- The payment handles you enter — Satispay, Revolut, PayPal, IBAN — so that people who owe you can pay you. Only people who share a group with you can see them.
- A technical identifier for your account, generated by us, linking your profile to your email.
- If you enable notifications: the push token, platform, device language, time zone and quiet-hours preferences. They are used only to deliver alerts to the right device at the chosen time.
- If you send feedback: the category and message text. You may choose to include technical diagnostics; in that case the message includes app and operating-system version, sign-in state, queued operations count, last sync and the latest technical warnings logged by the app.
- The two photos you can choose: your profile portrait and a group cover. They have a section of their own below, because an image is not a piece of data like the others.
- Your nickname, the language and the currency you pick, and a group’s start and end dates — which are also what the two end-of-trip reminders come from.
- The budget you set yourself in a group, if you set one: the amount and its currency. It keeps your cap on every phone you sign in on, and it is what the alerts about using it up are based on. Only you can see it: the database rules tie it to your account, and not even the people in your group can read it.
All of your groups go to the server
Syncing is per account, not per group: as soon as there is a connection, every group on this phone is copied to the server, including the ones you have never shared with anyone. There is no switch to keep one out, and we would rather write that here than let you find out.
It is the other side of what the account gives you: if the phone breaks or you replace it, your accounts are still there. What other people can read stays limited to the groups they belong to — a group that is only yours is seen only by you — and that limit is enforced by the database rules, not by the app.
Photos
Two photographs can leave this phone, and you choose them both: your profile portrait and a group cover. You pick them from your library — a cover you can also take on the spot — and before they leave, the app shrinks and compresses them here, never sending the original. Your portrait is seen by the people who share a group with you; a cover is seen by whoever is in that group. You can remove them from your profile or the group whenever you like and they go from the server too; delete the account or the group and they go with it.
No other photograph leaves here. When receipt scanning arrives, text recognition will happen on your phone, using the built-in iOS and Android capabilities: receipt photographs will not be uploaded anywhere and no cloud AI model will see them.
If we ever offer a paid cloud archive, it will be a separate and explicit choice, and this document will be updated before it exists.
Camera, library and motion
The camera is used for two things: reading the QR code that invites you into a group, and taking a group cover, if you choose to shoot one on the spot. Of the QR we read the code in the frame and nothing remains; of the cover the photo remains, and it is the one the section above is about. We never use the microphone.
Your library opens only when you pick one of those two photos, and the phone is what opens it: the app receives the single file you chose, not the list of your photographs. The motion sensor, lastly, is used only to open the feedback screen more quickly when you shake the phone: motion data is neither stored nor sent.
Notifications
Some reminders come from time passing — a debt left open, the end-of-month recap — and they are built and scheduled by your phone, without going anywhere.
Alerts about what other people do are a different matter, and it deserves spelling out. If you have an account and grant permission, your phone registers a device token with us, together with platform, language, time zone and quiet-hours preferences. When somebody adds or edits an expense in a group you share, our server writes the text and hands it to Expo, which routes it to Apple (on iPhone) or Google (on Android) for delivery.
Two more reminders come from our server, and they hang on a group’s dates: the day it ends — “you’re back, add the last expenses” — and a few days later, if the accounts are still open. The server prepares them rather than the phone because they have to reach people who have not opened the app in days, and they travel the same road as the other alerts.
A notification’s visible text contains the first name of whoever performed the action, the group name, expense description and amounts. The message also contains an internal technical identifier to open the right screen in the app. Never surnames, never your email address, never an IBAN or a payment handle — because a notification is read on a lock screen, in the hands of whoever picks it up.
We remove the token when you sign out or delete the account; if the app is uninstalled, Expo may later tell us that the device is no longer registered and we then remove it. You can switch off any kind of alert — or all of them — under "Notifications" in "You". With no permission we do not register the token, and Tacca still works in full.
Feedback, diagnostics, updates and exchange rates
Feedback is optional. It is read by our support team together with your account identifier and email address to handle the request. If you choose to include diagnostics, check the text before sending: the latest technical messages may contain information you entered in the app.
We use Expo Updates to distribute app updates; its service may receive the technical data needed to select a compatible version. For visual currency conversion, the app queries Frankfurter with the requested currencies only; it does not send groups, expenses or account identifiers, although the network provider may still see ordinary technical request data such as an IP address.
The anti-bot check
When you create an account or accept an invite by scanning a QR code, before the request reaches our server we check it with Turnstile, from Cloudflare: an automatic check that tells a person apart from a program, and that normally asks nothing of you — no traffic lights to pick out, no box to tick.
To do this, Cloudflare looks at a few technical signals of the request — not the content of what you write, just things like the IP address and device characteristics — under its Turnstile Privacy Addendum (www.cloudflare.com/turnstile-privacy-policy). It exists to stop anyone from mass-creating fake accounts or fake guest sessions: without it, knowing our project's address would be enough to do that without even going through the app.
The website, and anyone who leaves an address
This document covers usetacca.com too, where you may well be reading it right now. The site is made of pages written in advance, with no process running behind them: no cookies, no analytics, nothing loaded from anyone else, and nothing that could follow you from one page to the next.
At the foot of the home page there is one field, and it is the only thing the site asks you for: an email address, so we can tell you when Tacca reaches the stores. Leaving it is your choice and the site works just the same if you do not — the basis is your consent (art. 6.1.a GDPR), which you can withdraw whenever you like by writing to us.
We do nothing else with that address. Alongside it we keep the language you were reading in, so we write to you in that one, and the day you left it. No name, no IP address, no profile: the address sits in a table nobody can read from outside, not even the site that wrote it. You will get one email, on the day it comes out, and we will not use it for anything else or give it to anyone.
We delete it once the announcement has gone out. If you change your mind before then, write to us and we will remove it straight away.
Why we are allowed to (legal basis)
We process the data of synced groups to perform the service you asked for (GDPR art. 6.1.b): without it, syncing cannot work.
We process your email address for the same reason: it is how we authenticate you. Voluntary feedback is processed to handle your request and for service security and improvement; where needed, the legal basis is our legitimate interest (GDPR art. 6.1.f).
The address left on the website to be told about the launch is the only one we handle on the basis of your consent (art. 6.1.a GDPR): you typed it yourself, into a field you could have left empty, and you can withdraw it by writing to us without having to explain why.
We do not profile you and we make no automated decisions about you.
Where it physically lives
Synced application data lives on Supabase, hosted on Amazon Web Services infrastructure. The database is configured in the eu-west-1, Ireland region.
Supabase acts as data processor: it processes data on our behalf and on our instructions, never for its own purposes.
Every table is protected by access rules enforced by the database itself: an authenticated person can read only the data of groups they belong to. This is not a check written in the app — which could be bypassed — but in the database.
For login codes we use Supabase Auth and the configured SMTP provider; for anti-bot checks, notifications and updates we use Cloudflare, Expo and, for push delivery, Apple or Google. These providers may process technical data outside the European Economic Area under their own transfer safeguards and terms, so we do not claim an absolute absence of third-country transfers.
For how long
The data of a synced group stays as long as the group exists. When deletion from the app succeeds, your profile, email address, device tokens and associated feedback are deleted from the server; requests sent by email are handled within the statutory time limits.
One consequence of working in groups deserves attention: expenses you entered in a shared group stay visible to the other participants after you leave. They are part of their accounting history too, not only yours, and deleting them unilaterally would falsify other people's balances.
Feedback without account deletion is kept for as long as necessary to handle the request and maintain a support history; there is currently no separate automatic deletion for those messages.
From "You → Data" you can empty this phone whenever you like, but that is a local clean-up: as long as the account exists your groups are still on the server and come back at the next connection. To delete them for good you have to delete the account, from "You → Profile".
The address left on the website we keep until the launch announcement has gone out, and then we delete it: its expiry is written into the very reason it exists. If you ask sooner, we remove it straight away.
What we never do
This list is the most useful part of the document, because it is where apps are usually vague:
- We never sell, rent or hand over your data to anyone.
- We show no advertising and share nothing with ad networks.
- We use no behavioural analytics tools or advertising SDKs. We look only at internal aggregated counts for service health, without individual profiles or tracking a person’s actions.
- We do not profile you and infer nothing about you from your spending.
- We do not read your data to train AI models.
- We use no tracking cookies: the app is not a website and has none, and our site sets none.
Your rights
Over the data you entrust to us you may exercise the rights in GDPR articles 15-22: know what we hold, obtain a copy, correct it, erase it, restrict processing, object, and take it elsewhere in a readable format.
To exercise them, write to privacy@usetacca.com. For erasure you do not need to ask: it is under "You → Profile → Delete your account", and if you no longer have the app installed you can start it at https://usetacca.com/en/delete-account/: confirm a one-time code sent to your email address, then receive a receipt. The request is irreversible and a scheduled job deletes the account and associated data within thirty days.
When you delete your account, your profile, your nickname, your email address and your devices’ identifiers are gone. In groups you shared with other people your seat stays — a name inside a list of expenses — with no account attached: those expenses are theirs too, and shares already split still have to add up. Groups where nobody else is left are deleted along with the account.
If you believe we are handling your data improperly you may complain to the Italian Data Protection Authority (www.garanteprivacy.it) or to the authority of the country where you live.
Minimum age
To sign up you must be at least 14, the age at which Italian law lets you consent to the processing of your own data in digital services on your own. Below that age, the consent of a parent or guardian is required.
The example group can be viewed without an account: in that case we collect nothing and there is no age limit.
If this document changes
If we change anything substantial we will tell you inside the app and ask for your agreement again: we do not treat a change as binding merely because we published it.
Every version carries its date, and the one you agreed to stays recorded on your device.