Tally
Connector Privacy Policy
This policy explains how the Tally workout app and its Claude connector (the
Model Context Protocol server at https://mcp.tallyworkout.app/api/mcp) handle your data
when you connect Tally to Claude.
Who we are
Tally is operated by Vegh Labs LLC. For any privacy question or request, contact support@tallyworkout.app.
What the connector accesses
When you connect Tally to Claude and ask Claude to plan or review workouts, the connector — acting only for your signed-in account — can:
- Read your upcoming planned workouts and recent workout summaries.
- Read your completed workout history in set-by-set detail: exercises, weights, reps, durations, distances, ratings, and any notes you logged.
- Search the public exercise library by keyword — only your search term is sent, no personal data.
- Create or update future planned workouts in your account.
All access is scoped to your account only, enforced server-side by per-user row-level security. The connector never reads or writes another user's data.
What we store, and where
- Your workout data (planned workouts and completed sessions) is stored in our database (Supabase) as part of normal Tally use — the connector reads and writes that same data; it does not create a separate copy.
- Connection credentials: when you authorize Claude, we store OAuth tokens only as irreversible SHA-256 hashes (never in plaintext), with the client identifier and granted scope. Authorization codes are likewise stored hashed and are single-use.
- We do not store the contents of your Claude conversations. Data you ask Claude to read is returned to Claude (Anthropic) to answer you; Anthropic's handling of it is governed by Anthropic's own privacy policy.
What the connector does not collect
- It does not expose your name, email, account settings, or app preferences to Claude.
- Standalone cardio entries stay on your device only and are never synced or shared through the connector.
Data retention
- Access tokens expire after 1 hour; refresh tokens after 30 days.
- Disconnecting — signing out of Tally on a device, or removing the connector in Claude — immediately revokes your tokens.
- Deleting your Tally account permanently deletes your workout data and all connector tokens and authorization codes.
Third parties
- Supabase — database and authentication.
- Vercel — hosting for the connector.
- Anthropic (Claude) — the connector client; receives the workout data you ask Claude to read.
- exerciseapi.dev — public exercise library; receives only your search keywords.
- Apple / Google — only if you choose those sign-in methods.
Your choices
- Disconnect anytime by signing out in the Tally app or removing the connector in Claude.
- Delete your account in Tally (Settings → Account) to erase your data and revoke all access.
- Contact support@tallyworkout.app with any privacy question or request.
Changes
We may update this policy; the effective date above reflects the latest version.