How does Tally protect your sign-in?

With passkeys or a long password, one-time codes for pairing a phone, a separate sign-in for each device and an HTTPS connection. This page says what is built, in plain words, and what is not claimed.

How do I sign in?

Two ways are built: a passkey, or a username and password. Both give you a session.

Sign-in details
TopicHow it works
PasskeysSign in with the passkey on your device instead of typing a password.
PasswordsAt least 12 characters. Stored only as a salted hash, never as the password itself.
Failed attemptsSlowed down, so guessing passwords gets harder with every miss.
Setting a passwordA password is set from the server's command line, not on a web page. There is no public sign-up page.
Lost passkey or passwordThere is no self-service forgot-password page. The person who runs the server can issue a one-time recovery link.

How does pairing a phone work?

A one-time code, typed or scanned, that works once and expires in 5 minutes.

  1. Show a code

    In the web app, choose Pair a phone. It shows a one-time code and a QR code.

  2. Enter it on the phone

    Type the code on the phone, or scan the QR code with the phone camera. There is no scanner inside the app.

  3. The phone gets its own sign-in

    The phone receives a device sign-in that is separate from your password. The server stores it only as a hash.

  • The code works once and expires in 5 minutes.
  • On the phone, the device sign-in is kept in the Android secure key store.

How do I revoke a device?

In the Android Budget settings there is a revoke dialog, and the server can list and revoke paired devices. The website has no device list or revoke button yet.

What does the session cookie do?

It is the small note your browser sends so the server knows you are signed in.

Session cookie basics
PropertyPlain meaning
HttpOnlyScripts on the page cannot read it.
SameSite=LaxIt is not sent along with most requests that start on other sites.
About 30 days, slidingIt lasts about a month and keeps extending while you use the app.
Stored as a hashThe server keeps a hash of it, not the cookie value itself.

What about HTTPS and backups?

The hosted site is served over HTTPS, and its database is copied every day.

Transport and backups
TopicDetail
HTTPSThe hosted site is served over HTTPS with a Let's Encrypt certificate. The app container has no open port of its own.
Daily backupsThe database is copied every day at 03:15 and 14 daily copies are kept.
Before upgradesA backup is also taken before a database upgrade.

Questions about what is stored?

Tally is in development and not open for sign-ups yet. The privacy page lists everything the server keeps.