Effective Date: May 14, 2026 | Last Updated: June 2, 2026
"TallyPrime" means the business management software developed and owned by Tally Solutions Private Limited ("Tally"), deployed locally by users to manage accounting, compliance, inventory, and financial operations.
TallyPrime utilizes industry-standard OAuth 2.0 authentication protocol to securely send business documents, such as invoices and reports, directly from your application. This secure method allows TallyPrime to connect to your email provider without accessing, requesting, or storing your account password.
This section outlines our commitment to data privacy and security for specific email providers.
A. Google API Services (Gmail)
What Gmail Data We Access (and Why)
When you connect your Gmail account, we request a minimal set of OAuth scopes necessary to provide email sending functionality. The exact scopes are displayed on the Google consent screen and are limited to:
Scopes we request
| Scope | Why we need it |
|---|---|
| openid | To complete the OAuth sign-in and obtain a unique identifier for your Google account. |
| email: https://www.googleapis.com/auth/userinfo.email | Used to get your Google account email so TallyPrime knows which account is connected for sending. |
| https://www.googleapis.com/auth/gmail.send | Allows sending emails through Gmail on behalf of the logged-in user. This requires a special restricted permission under Google's policy. |
What Gmail Data We Access
Our application is designed as a send-only implementation.
Data we access:
The information entered in Tally is sent directly to Google's mail servers through the API. Tally does not access or store the email content. Only limited technical data (such as telemetry or metadata), which does not identify the user, may be temporarily stored.
Data we DO NOT access:
We do not access, read, retrieve, or process any existing data from your Gmail account, including:
Our application cannot view or read your mailbox at any time.
Restricted Scope Clarification
We do NOT request or use any restricted Gmail scopes, including:
This ensures that your email content remains completely private and our access is limited strictly to sending emails you initiate.
How Email Sending Works
When you send an email via our application:
We use this data only at the time of sending and:
What we store & what we don't — Data Storage and Tokens
We do not store any email data or mailbox content. We do not engage in automated analysis of message content beyond what is required to display and send your email.
Retention
Security
Tally does not store or process the content of emails sent through this integration. Email content (subject, body, recipients, and the attached report) is sent directly from your TallyPrime application to your email provider via their API and is not stored on Tally's servers.
Your choices & controls
Revoke app access (Google account controls)
Disconnect & delete tokens
You can log out from TallyPrime at any time, which immediately removes the tokens from the application and deletes them from Tally's servers. Tokens are also automatically deleted if not used for 7 days.
Data portability
Your Gmail data remains in Gmail. Because we do not store message content, there is no additional export to provide beyond what Google already offers.
Sharing & transfers
Data transfers
All TallyPrime services for this integration are hosted and processed in India. If you access the service from outside India, your information will be transferred to and stored in India in accordance with applicable laws. Gmail message content itself remains with Google unless and until you view it in the UI.
Children's privacy
TallyPrime is not directed to children. Do not use the Gmail integration if you are under the minimum age.
How Sign-in works in your browser
We use essential session cookies or local storage for authentication and to maintain state within the webmail UI. During OAuth sign-in, your browser interacts directly with your email provider's pages, and any cookies or local storage set at that stage are governed by your email provider's policies. We do not use email data for advertising or cross-site tracking.
Compliance with Google API Services User Data Policy
Our use of Google user data complies with the Google API Services User Data Policy, including the Limited Use requirements.
B. Microsoft Graph API (Outlook / Office 365)
The following supplemental terms and technical standards apply to all OAuth-based email integrations within TallyPrime:
You may refer to the TallyPrime Policies for further information: