Privacy Policy
Effective: 22 April 2026 ·
Version 1.0
TallyComm is a broadcast tally light and intercom system for smartphones, operated by Noctavox ("we", "us"). This policy explains exactly what data we collect when you use the TallyComm web app, iOS app, TallyBridge desktop app, or the Bitfocus Companion module, how we use it, and what rights you have over it.
Short version: we collect the minimum needed to run the service (your email and name for your account, event/session data, usage minutes). We never record or store audio content. We don't sell data, run ads, or track you across other apps and websites.
TL;DR
- We collect email, name, and event data. Never audio.
- We share data only with three service providers (LiveKit for audio transit, Resend for email delivery, Apple for distribution).
- You can delete your account and all data from the app at any time.
- No ads, no analytics trackers, no cross-site tracking.
1. Data We Collect
Account data (organizers)
When you sign up as an organizer by email magic link, we store:
- Email address — required, used for magic-link sign-in and account recovery.
- Display name — optional, shown to your teammates in intercom channels.
- Organization, country, preferred language — optional, for profile customization.
- Subscription tier (trial, pro, or expired), trial start date, monthly minutes used, and timestamps (
createdAt, lastLoginAt).
Event data
When you create or join an event:
- Event code and name (chosen by the organizer).
- Member roster: name, role (cam / crew / director), camera number, cargo.
- PINs used to sign in operators — stored as SHA-256 hashes only. Plain-text PINs are kept only long enough to display them to the event owner on the dashboard, then can be rotated by the owner.
- Tally state (PGM / PVW per camera) during an active event, persisted to disk so it survives server restarts.
- Intercom log: who spoke on which channel and when, capped at the last 500 events per room, held in memory only (not persisted across server restarts).
- Switcher integration API key (tallyKey) for Companion / TallyBridge — PRO tier only.
Session data
- Operator session tokens — 24h TTL, issued when an operator signs in with a PIN.
- Account session tokens — 90d sliding TTL, stored as HTTP-only cookie (web) or in app
localStorage as a Bearer token (iOS app, due to cross-origin cookie restrictions in WKWebView).
- Magic-link tokens — 15 min one-use TTL, deleted after use.
Usage metrics
We record aggregate usage for capacity planning and subscription tier enforcement:
- Connection minutes per room per day.
- Peak concurrent clients per room.
- Event count and session count per day.
Daily buckets are retained for 30 days then overwritten. No per-user behavioral tracking.
Transient data (not stored)
- Audio — voice packets travel in real time through LiveKit Cloud during an active event. They are not recorded on your device, not stored on our server, and not retained by LiveKit beyond the live transit.
- IP addresses — used only by in-memory rate-limiters to prevent brute-force PIN attempts (5 failures → 30 min lockout per IP). Not written to disk, not linked to your account.
Data we do NOT collect
- Location data, GPS coordinates.
- Phone numbers, physical addresses.
- Payment or credit card information (upgrades are handled manually by email).
- Contact lists, photos, files outside the app.
- Advertising identifiers (IDFA, Google Advertising ID).
- Browsing history across apps or websites.
2. How We Use Your Data
- Run the service: route tally signals, send intercom audio, validate sign-ins, enforce tier limits.
- Communicate with you: magic-link sign-in, welcome email, upgrade confirmation, critical service notices. We don't send marketing email unless you opt in.
- Improve the product: aggregate usage metrics (never individual behavior) to plan capacity and feature priorities.
- Secure the service: IP rate-limiting on sign-ins to prevent brute-force attacks.
Legal basis (GDPR): performance of the contract with you (running the service you signed up for), our legitimate interest (security, capacity planning), and your consent where required (optional profile fields).
3. Third Parties We Share With
We use three service providers. We don't sell data to anyone.
| Provider |
Data shared |
Purpose |
| LiveKit Cloud |
Your display identity, audio stream (in transit only) |
Real-time audio routing for intercom |
| Resend |
Email address, magic-link URL |
Email delivery (sign-in links, welcome messages) |
| Apple Inc. |
App download metrics, crash reports (if opt-in) |
iOS app distribution via App Store / TestFlight |
We may also disclose data if required by law (court order, subpoena) or to protect our rights and safety. We will notify affected users where legally permitted.
4. How Long We Keep Data
| Data |
Retention |
| Account (email, name, profile) | Until you delete it |
| Events you own | Until you delete them |
| Operator session tokens | 24h |
| Account session tokens | 90 days (sliding) |
| Magic-link tokens | 15 minutes or until consumed |
| Usage metrics (daily aggregates) | 30 days |
| Intercom event log (per room) | In memory, cleared on server restart |
| Tally state (per room) | Until room is deleted |
5. Security
- All traffic uses HTTPS / TLS. WebSocket traffic uses
wss:// (encrypted).
- PINs are stored as SHA-256 hashes, never in plain text on disk.
- Cookies are
HttpOnly, Secure, and SameSite-scoped.
- Rate-limiters block brute-force attempts (5 failures → 30 min lockout).
- We don't store passwords. Sign-in is either PIN (for operators) or magic-link (for accounts).
- Standard security headers (HSTS, X-Frame-Options, CSP-lite, Referrer-Policy).
No system is 100% secure. If we detect a breach affecting your data, we will notify affected users within 72 hours by email.
6. Your Rights
Regardless of where you are, you have these rights over your data:
- Access: see your account and events at any time in the dashboard.
- Edit: update your name, organization, country, and language in the profile page.
- Delete: delete your account + all owned events from the profile "Danger Zone". Action is irreversible.
- Revoke sessions: sign out of all devices at once from the profile page.
- Export: request a JSON export of your data by emailing hello@tallycomm.com. We respond within 30 days.
- Complain: if you're in the EU/UK, you can lodge a complaint with your local data-protection authority.
7. Children's Privacy
TallyComm is a professional broadcast tool and is not directed at children under 13. We don't knowingly collect data from children under 13. If you believe a child has signed up, email hello@tallycomm.com and we'll remove the account.
8. International Users
Our servers are located in the United States. By using TallyComm from outside the US, you consent to the transfer and processing of your data in the US.
For EU/UK users: we rely on Standard Contractual Clauses with our sub-processors (LiveKit, Resend) where applicable.
9. Changes to This Policy
We may update this policy when we launch new features or change data practices. The "Effective" date at the top of this page reflects the latest version.
For material changes (new data types collected, new sub-processors, changes to your rights), we will notify account holders by email at least 14 days before they take effect.
10. Contact
Questions, requests, complaints?