⚠️ Draft — to be completed with the data controller's details and reviewed by a legal professional before launch.
Privacy Policy
Last updated: 20 June 2026
This policy describes how Tanily processes the personal data of app and website users, under Regulation (EU) 2016/679 (“GDPR”) and Italian Legislative Decree 196/2003. We use plain language: if you have questions, write to ciao@tanily.it.
1. Data controller
The data controller is [Company / controller name], [address], VAT [VAT number]. For any request about your data, write to ciao@tanily.it.
No Data Protection Officer (DPO) has been appointed: [DPO contact details, if appointed].
2. Data we process
- Account data: email, name, password (encrypted), avatar, family role.
- Content you enter: financial data (accounts, transactions, budgets, savings, loans, vehicles, assets), calendar events, tasks, attachments (e.g. receipts, photos).
- Children's profiles: name and optional date of birth, entered and managed by the parent (see §4).
- Subscription data: plan, status, renewal dates. Payment data (card) is handled directly by the payment providers: we do not store it.
- Notifications: device identifier (push token) to send you reminders.
- Technical data: system logs, IP address, device type, needed for security and operation of the service.
3. Purposes and legal bases
| Purpose | Legal basis (Art. 6 GDPR) |
|---|---|
| Provide the service (account, finances, calendar, tasks, notifications) | Performance of the contract (1.b) |
| Manage subscriptions and payments, issue invoices | Contract (1.b) and legal obligation (1.c) |
| Security, abuse prevention, logs | Legitimate interest (1.f) |
| Non-personalized ads on the Free plan | Legitimate interest (1.f) — see §5 |
| Service communications (transactional email) | Contract (1.b) |
The financial data you enter is personal data but not a “special category” under Art. 9 GDPR. We do not carry out financial profiling or automated decision-making on your data.
4. Children's profiles (minors)
Tanily is designed for families. Children are not direct users: they are profiles created and managed by the parent (or holder of parental responsibility), who is the adult account holder and warrants the right to enter such data. In Italy independent digital consent is possible from age 14; for children under 14, the holder of parental responsibility provides it. We collect only the data strictly necessary (data minimization) and never show ads on children's profiles.
5. Advertising
On the free plan we show discreet, non-personalized ads via Google AdMob. “Non-personalized” means we do not use your data to profile ads, so no tracking consent is required. Ads are never shown during the trial, to Premium users, or on children's profiles. AdMob may process device identifiers and usage data to deliver and measure non-personalized ads.
6. Recipients and processors
To run the service we use providers that process data on our behalf (sub-processors):
| Provider | Purpose | Notes |
|---|---|---|
| Stripe | Subscription payments (web) | USA — SCC/Data Privacy Framework |
| RevenueCat, Apple, Google | In-app purchases on stores | USA — SCC/DPF |
| Google AdMob | Non-personalized ads (Free) | USA — SCC/DPF |
| Google Firebase (FCM) | Push notifications | USA — SCC/DPF |
| Resend | Transactional email | USA — SCC/DPF |
| Hosting provider | Infrastructure and storage | [provider and location] |
Data stays within the European Economic Area where possible; any transfers to third countries (e.g. USA) rely on Standard Contractual Clauses or the Data Privacy Framework. We do not sell your data.
7. Retention
- Account data and content are kept while the account is active.
- On account deletion, personal data is erased; some data may be kept as needed to meet legal obligations.
- Tax documents (e.g. invoices) are kept for 10 years as required by law.
8. Your rights
You have the right of access, rectification, erasure, restriction, portability and objection (Arts. 15–22 GDPR). You can exercise them by writing to ciao@tanily.it. You also have the right to lodge a complaint with the Italian Data Protection Authority (garanteprivacy.it).
9. Security
We apply appropriate technical and organizational measures (Art. 32 GDPR): encryption in transit (HTTPS/TLS), hashed passwords, controlled access and per-family data isolation.
10. Cookies
This site uses only technical cookies necessary for operation, which do not require consent. We do not use profiling or marketing cookies. Should we introduce analytics or marketing tools in the future, we will update this policy and show a consent banner.
11. Data breaches
In case of a personal data breach posing a risk to your rights, we notify the supervisory authority within 72 hours of discovery and, where the risk is high, inform the affected users (Arts. 33–34 GDPR).
12. Changes
We may update this policy; the date at the top shows the latest revision. Material changes will be communicated to you.
13. Contact
For any privacy matter: ciao@tanily.it.