Privacy Policy
Last updated: September 24, 2026
This policy explains what TallyWeek collects, why, who processes it, how long we keep it and what you can ask us to do. AiroxLab LLC is the controller of the data described here.
1. What we collect
- Account details. Your email address, the name you enter and, if you add one, an avatar image. You can also add optional profile details such as a job title, phone numbers, location, birthday and work anniversary; these are shown to members of your workspaces.
- Google sign-in. If you sign in with Google, Google shares your name, email address and profile picture with us. We use them to create or match your account. We do not receive your Google password or any other Google data.
- Workspace content. Everything you and your workspace members create: boards, items, column values, updates and @mentions, files you upload, automations, dashboards and activity history. This content may include personal data about other people, for example your clients or staff. You are responsible for having a lawful basis to put it in TallyWeek.
- Public form submissions. When someone fills in a form you publish, whatever they enter becomes an item on your board. We store it for you; you control what is asked and what happens to it.
- Technical logs. IP address, browser user agent, request paths and timestamps are recorded in server logs and used for security and debugging. A hash built from your user ID, IP address and user agent is used to recognise a signed-in session.
- Cookies and local storage.A cookie holds your sign-in session. Your theme preference (light, dark or system) is stored in your browser's local storage. We do not use advertising or tracking cookies.
- Billing. When you pay for a plan, the payment provider collects your card details directly. We receive the outcome of the payment, the billing name and address if given, and invoice records. Card numbers never reach TallyWeek servers.
- Support messages. Emails, calls and texts you send to us, so we can answer them and keep a record of what was agreed.
2. Why we use it
- To provide TallyWeek: sign you in, show your workspaces, run automations, deliver notifications, serve files and answer API requests.
- To bill paid plans and keep tax and accounting records.
- To send transactional email: invitations, password resets, mention and assignment notifications, due-date reminders and billing receipts. You can turn most notifications off in your settings; security and billing messages cannot be turned off while you have an account.
- To keep the service secure, prevent abuse and investigate problems.
- To respond to support requests and complaints.
- To meet legal obligations.
We do not sell personal data. We do not use your content for advertising, and we do not use it to train machine-learning models.
3. Processors we use
We use a small number of providers to run TallyWeek. Each one processes data only on our instructions and only for the purpose listed.
| Provider | What it does | Data involved |
|---|---|---|
| AiroStack (self-hosted platform) | Database, authentication and file storage | Account details, hashed passwords, workspace content, uploaded files |
| Vercel | Hosts the application and serves requests | Request logs including IP address and user agent, content in transit |
| Resend | Sends transactional email | Recipient email address and the content of each message |
| Payment provider (named on your receipt) | Takes card payments and issues receipts | Card details, billing name and address, payment history |
| Optional sign-in | Name, email address and profile picture, only if you choose Google sign-in |
We do not load third-party analytics or advertising scripts inside the application.
4. Who can see your data
- Members of your workspace, according to the roles and board permissions your owner and admins set. Private boards are visible only to the people shared on them.
- Anyone holding an API key for your workspace, limited to what the acting member and the key's scopes allow.
- Our team, only when needed to support you, investigate abuse or fix a fault, and under confidentiality obligations.
- Authorities, if the law requires it. We tell you when we are allowed to.
5. How long we keep it
- Workspace content and account details: for as long as the account or workspace exists. Trashed items and boards can be restored by your workspace until they are permanently deleted.
- Deleted accounts and workspaces: removed from our systems within 30 days of the request.
- Server logs: kept for a short rolling period for security and debugging, then discarded.
- Billing and tax records: kept for as long as the law requires, typically seven years.
- Support correspondence: kept for up to three years after the matter closes.
6. Your rights
Wherever you are, you can ask us to:
- Access the personal data we hold about you.
- Export your workspace data. You can do this yourself at any time through the REST API, or ask us and we will send an export.
- Correct details that are wrong. Most account details can be edited in your profile.
- Delete your account or workspace. We complete deletion within 30 days, except for records we must keep by law.
- Object to or restrict certain processing, and complain to a data protection authority where one applies to you.
Send requests to info@airoxlab.com. We may ask you to confirm your identity first. We reply within 1 business day.
If someone else's workspace holds data about you (for example, you filled in one of their forms), the workspace owner controls that data. Contact them first; we will help them respond.
7. Children
TallyWeek is for people aged 16 and over. We do not knowingly collect data from anyone under 16. If you believe a child has created an account, tell us and we will remove it.
8. International transfers
AiroxLab LLC is a United States company registered in Wyoming, USA. Data is stored and processed on infrastructure operated by the processors listed above, in the regions they operate. By using TallyWeek you understand that your data may be accessed from the United States and processed where our providers run their systems. Where a data-processing agreement or specific transfer terms are required for your organisation, ask us about the Business plan.
9. Security
How we protect data is described on the Security page. No system is perfectly secure; if we discover a breach affecting your personal data, we will tell affected workspace owners without undue delay.
10. Changes to this policy
We may update this policy. For material changes we email workspace owners at least 14 days before the change takes effect. The date at the top shows the current version.
11. Contact
- Email: info@airoxlab.com
- Phone: +1 (320) 842-1112
- AiroxLab LLC, 30 N Gould St, Ste R, Sheridan, WY 82801-6317, United States
Related: Terms of Service, Acceptable Use Policy, Ownership Statement.