Last updated August 29, 2026
Most apps send everything you write to a company's server. dally mostly doesn't, and where it does, this page names it.
Everything you create in dally, your trips, bookings, receipts, notes and photos, is stored in your own iCloud account, using Apple's CloudKit service. dally can't see it any more than a filing cabinet can see what's inside it.
Alongside that, dally runs one small server at planwithdally.com, on Cloudflare. It exists for four jobs: the page that lets a table split a bill, the community counts and photographs on Explore, generating destination artwork, and shipping small settings files to the app. Your trips are never on it.
There is a third place worth naming, because most policies leave it vague. A few specific things go into the public part of dally's iCloud database, where they are readable by the app for everyone rather than only by you: the destination artwork, an invite board when you make one, and the anonymous import diagnostics. Each is described in its own section below, and nothing else goes there.
dally is built and run by Kevin Kheira, an independent developer, not a company with a data team. Kevin is the person responsible for the choices on this page, referred to in some privacy laws as the "data controller."
dally uses Sign in with Apple to identify you. Depending on what you allow Apple to share, dally may receive:
Your name and photo, if you add one, appear to people on trips you share with them. Your email address is different: dally stores it privately on your own account and never shows or shares it with anyone, including other people on your trips. It exists so your identity can be restored if you sign in again on a new device.
You can also add a home airport and a profile photo. Both are optional, and both live in your private iCloud record.
When you delete your account, dally asks Apple to revoke the sign-in token as part of the same action, so the connection between your Apple ID and dally is cut rather than just forgotten.
Everything you add to a trip is stored in your iCloud account: flights, stays, tables, outings, notes and receipts, including receipt photos and amounts.
When a trip is shared, everything on that trip is visible to the people you shared it with. An earlier version of dally offered a per-item "Only me" switch. It was a filter drawn on your own screen rather than a real boundary, so it has been taken out rather than left there implying a protection it couldn't deliver. If something shouldn't be seen by the group, keep it on an unshared trip.
Receipt photos are stored on your device and, when the trip syncs, in your iCloud. They ride the trip's share to the people on it. They are never uploaded to dally's own server, and never attached to a claim link.
This is the one part of dally where something you made is stored on dally's own server rather than in your iCloud, so it gets its own section.
When you turn a receipt into a claim link, dally sends the bill to its server so a web page can show it to people who don't have the app. What gets sent is:
What is never sent: the receipt photo, anyone's last name, email or phone number, the trip's name, your notes, or any device identifier. There is no column for them.
Anyone holding the link can read the bill and tap the lines that were theirs, or add themselves by first name. That is what makes it work in a group chat without anyone installing anything, and it is also its limit: the link is the key. Only the phone that created the link can change the bill itself.
Claim links delete themselves after seven days, automatically, whether or not anyone used them. You can also stop one at any time from the receipt, which deletes it immediately. When you delete your dally account, every live claim link you made is stopped as part of that.
Explore shows places to go. Most of what's on it is dally's own suggestion, marked "dally picks."
Some of it is earned instead. When you save, plan or visit a place, dally sends a small signal to its server: the place, its city and country, what kind of place it is, whether you saved, planned or visited it, and the month. It does not include your name, your account, your trip, or a date more precise than the month.
Those signals are tied to a random identifier created on your device, not to your account, and the server stores only a scrambled version of it, so a row can't be traced back to a person. A place only ever appears with real counts once at least five different people have contributed, and that floor is applied when the answer is assembled, so a place below it is never in a response at all.
This is the one thing in dally that is on without a switch of its own. If you would rather not contribute, don't save, plan or mark places as visited, and nothing is sent. These signals are kept indefinitely and are not removed when you delete your account, because there is nothing in them that identifies you to find and remove. See the retention table below.
The photographs on Explore come from the same server. Where a public-domain or freely licensed photograph of a city exists, that's what you see. Where none does, the picture was generated by a machine in a single fixed style, made once for everybody, and reused. Explore never shows the hand-drawn destination art, which is only ever for somewhere you're actually going.
If you allow calendar access, dally looks through your device calendar to find events that look like flights or stays, so it can offer to build a trip around them.
That scan happens entirely on your phone. Your calendar's raw events are never uploaded, transmitted, or stored anywhere. Only the trip details you review and approve get saved, to your own iCloud, exactly like a trip you built by hand.
Weather usually comes from the coordinates of the place you're going, which dally already knows because you told it. No device location is needed for that.
If you switch on Weather where I am and allow location access, dally uses your approximate location, not precise GPS, to show weather for where you actually are. Your location isn't logged or kept as a history. It's used live, in the moment, to fetch a forecast.
Forecasts come from Apple's WeatherKit. If WeatherKit can't answer, dally falls back to Open-Meteo, a free weather service, and sends it the coordinates and nothing else: no name, no account, no identifier.
The camera is used only if you choose to photograph a receipt. dally doesn't browse or scan your existing photo library. You pick individual photos yourself when adding a receipt, a journal entry or a profile picture, the same way any app's photo picker works, and dally only ever receives the ones you picked.
When dally makes a poster or an invite card for your trip, it hands the finished image to the standard iOS share sheet, where saving it to Photos is one of the options you can choose. dally doesn't write to your photo library on its own.
dally reads things for you: a receipt photo, a booking confirmation you paste, a screenshot of an email. All of that reading happens on your phone.
Two Apple technologies do the work, both on-device. Vision finds the text in a picture. Apple's on-device language model then makes sense of it, turning a wall of text into a hotel with dates or a receipt with line items.
Nothing from any of these goes to a server. Not the photo, not the text, not the result. There is no cloud model in dally, and no chat. What the model produces is always filled into a fixed set of fields, like a form, rather than free writing, and you see and can correct every field before anything is saved.
If your device doesn't support Apple's on-device model, dally falls back to plain pattern matching, which also happens entirely on your phone.
There is one thing you can volunteer. If a booking imports badly, dally offers to send that one file so the reader can be improved. That's a deliberate, per-file tap, it's off unless you choose it, and it sends the document itself, which may contain your name and confirmation number. If you'd rather not, don't tap it, and nothing goes.
dally draws a line-art illustration of the places you go. To make one, it sends the name of the destination, for example "Tokyo," to Google's Gemini API through dally's own server, which acts as a service provider for that one narrow purpose.
No personal information, trip details, photos, or anything that identifies you is ever included in that request. It is the place name and a fixed description of the drawing style, and nothing else. The resulting artwork is cached and reused for everyone traveling to that destination, so the same request rarely happens twice. Google's own privacy policy governs how they handle that request on their end.
These pictures are made by a machine. The destination line-art is generated, and so are the city photographs on Explore when no freely licensed photograph exists. They are illustrations of a place, not photographs of it, and they shouldn't be read as a record of what anywhere actually looks like.
dally Pro is a paid subscription. If you buy one, Apple handles the entire transaction. Apple takes the payment, holds the subscription, sends the renewal reminders, and is where you cancel or ask for a refund.
dally never sees your card, your billing address or your payment details. What dally receives from Apple is the answer to one question: whether this Apple ID currently has an active subscription. That answer is checked on your device.
The full subscription terms, including how renewal and cancellation work, are in the terms of use.
When dally reads a pasted booking confirmation, it can share anonymous signals about how well that went, so the underlying logic can improve over time. The same switch covers a small signal about whether a settings file loaded correctly.
These describe the shape of what happened and never its content: whether it succeeded, which reader ran, how many pages there were, how many airport codes and dates were spotted, the airline or hotel brand if one was recognised, and a country-level region. It never includes the document's text, your name, or anything that identifies you.
This is on by default, and you can turn it off any time in Settings, under Your Data. The import diagnostics are stored in the public part of dally's iCloud database; the settings signal goes to dally's own server and carries no identifier at all.
dally also keeps a rolling sync log on your device, which you can read in Settings under Your Data. It stays on your phone and is never uploaded.
| Advertising | No ad networks, no ad identifiers, no ad tracking of any kind |
| Analytics SDKs | No Firebase, no Mixpanel, no third-party analytics of any kind. dally ships no third-party code at all |
| Cross-app tracking | dally can't see what you do in other apps, and doesn't try to |
| Selling your information | Never sold or shared for money, as those terms are defined under California and EU privacy law |
| Your contacts | dally doesn't read your address book |
| Your photo library | dally never scans it; you choose individual photos yourself |
| Training a model | Nothing you write is used to train anything, by dally or by anyone else |
| A chatbot | There's no chat in dally, and nothing you type is sent to a language model on a server |
You can delete any booking, note, or receipt at any time, or delete an entire trip. Delete account, in Settings, removes your account and your data together, and offers you a download of everything first.
You can also export your trips, bookings, and receipts as a spreadsheet, or make a full backup, anytime from Export all data in Settings. That's your information, in a format you can open anywhere.
| What | Where it lives | How long |
|---|---|---|
| Trips, bookings, notes, receipts and their photos | Your iCloud | Until you delete them, or delete your account |
| A deleted trip | Your device | Recoverable for 30 days, then gone |
| A shared bill behind a claim link | dally's server | 7 days, then deleted automatically. Immediately, if you stop the link |
| An invite board and any requests to join | dally's public iCloud database | Until you stop sharing, get a new link, or delete the trip or your account |
| Explore signals | dally's server | Kept indefinitely. Not linked to your account and not removed on account deletion |
| Settings-file signals | dally's server | Kept indefinitely. Contain no identifier at all |
| Import diagnostics | dally's public iCloud database | Kept indefinitely |
| A booking document you volunteered | dally's public iCloud database | Kept until removed by hand. Email to have yours removed |
| Destination artwork and Explore photographs | dally's server and public iCloud database | Kept indefinitely. They are pictures of places, with nothing personal in them |
| Your sync log | Your device only | Last 600 lines, and you can clear it |
Deleting your account stops sharing on trips you own, takes down their invite boards, quietly removes you from trips shared with you, deletes your trips and their photos from iCloud, deletes your profile, stops every live claim link you made, and asks Apple to revoke the sign-in.
Two things deliberately survive it, and it's better to say so than to imply otherwise. Trips you shared stay with the people you shared them with, frozen as their own copy, because their memory of the trip isn't yours to delete. And the anonymous signals described above stay, because they were never connected to you in the first place, so there is no row with your name on it to find.
If you want a volunteered booking document removed, or you're unsure whether something of yours is still out there, email support@planwithdally.com and it will be handled.
Wherever you live, you have real control over your information, not just because a law says so, but because of how dally is built.
You already have full access to everything dally has about you. It's right there in the app, in your trips, your profile, your settings. There's no separate request process to wait on, because there's no hidden copy to ask about.
Export all data, in Settings, gives you your trips, bookings, and receipts as a spreadsheet you can open anywhere, or a full backup file. That covers what privacy law calls the right to data portability.
Edit or delete anything yourself, a booking, a note, an entire trip, directly in the app. Because your private trip data lives only in your own iCloud account and dally keeps no separate copy, deleting it yourself is the complete, final word.
The exceptions are the anonymous signals and the shared trips described in the section above. Neither is tied to your identity in a way that could be looked up and removed, and the retention table says exactly how long each one lasts.
dally doesn't sell or share personal information for money or cross-context advertising, as those terms are defined under California law, so there's nothing to opt out of. dally also honors Global Privacy Control browser signals, though again, there's no sale or sharing for one to affect.
You'll never be charged more, denied a feature, or treated worse for exercising any of these rights. There's nothing to lose by asking.
If anything here doesn't cover your situation, or you'd rather not use the in-app tools yourself, email support@planwithdally.com. We'll respond within 30 days.
If you're in the EU or UK, you also have the right to lodge a complaint with your local data protection authority. California residents can contact the California Attorney General's office. You don't need to contact us first.
For readers who need the legal framing, and for anyone in the EU or UK:
| What | Why it's lawful |
|---|---|
| Running your account and syncing your trips | Performing the agreement you made when you started using dally |
| Sharing a trip, an invite board, a claim link | Performing that agreement, at your instruction, each time you choose to share |
| Location for weather, calendar scanning, camera | Your consent, given through the iOS permission prompt, withdrawable in Settings at any time |
| Import diagnostics and settings signals | Your consent, on by default and switchable off under Your Data |
| Explore signals | Legitimate interest in making Explore useful, weighed against the fact that the data is not linked to you and carries a five-person floor |
| Keeping dally standing up and safe from abuse | Legitimate interest in the service working |
dally is built by one developer, not a company with international offices, but the services it relies on are global. These are all of them:
| Service | What it does for dally |
|---|---|
| Apple | iCloud storage and sharing, Sign in with Apple, WeatherKit, Maps, and the App Store subscription |
| adsbdb | Flight routes. When you type a flight number, dally’s own server asks adsbdb which airports that flight flies between. It receives the flight number and nothing else, never anything about you |
| Cloudflare | Runs dally's own server: the claim pages, Explore counts and photographs, and settings files |
| The Gemini API, which receives a place name and returns a picture. Nothing else | |
| Open-Meteo | Weather, only when Apple's WeatherKit can't answer. Receives coordinates only |
| TikTok | Only if you save a TikTok link and agree to it, to fetch that video's title and cover image |
Apart from adsbdb, which receives no personal information at all, all of them are operated by companies headquartered in the United States. If you're in the EU, the UK or Switzerland, that means your information may be handled there, and each service uses a recognised legal mechanism for it: Cloudflare and Google are certified under the EU-US Data Privacy Framework, and Apple uses standard contractual clauses approved by the European Commission.
Their own privacy policies describe this in detail: Apple, Cloudflare, Google.
dally isn't directed at children under 13, and dally doesn't knowingly collect information from them. If you believe a child has used dally to create an account, contact us and we'll address it.
If this policy changes in a meaningful way, we'll update the date at the top of this page. We'd encourage checking back occasionally, but nothing here changes without a reason you could point to.
Questions about this policy, how dally handles your data, or a privacy request, can be sent to support@planwithdally.com.