Acceptable Use Policy (AUP)

Service: Simple Money Tracker ("Simple Money Tracker", "we", "us", "our")

Website: https://simplemoneytracker.com

Last Updated: 15/08/2026

This Acceptable Use Policy ("AUP") states what you may and may not do on the Service. It is part of your agreement with Simple Money Tracker.

Read it with the Terms of Use, Privacy Policy, Cookie Policy, License, and DMCA Policy.

By creating an account or using the Service, you agree to this AUP. If documents conflict: the Terms control billing and account status; the Privacy Policy controls personal data; this AUP controls allowed and prohibited use.


1. Purpose

The Service is a personal-finance record-keeping tool. This AUP exists to protect users, keep billing fair, and keep the platform secure.

You must be 18 or older, as stated in the Terms.


2. Permitted Use

You may use the Service to:

  • log and review your own finances (and shared group data you are invited to)
  • use optional features you are entitled to (AI, Telegram logging, storage, weather, currency conversion) within published limits
  • export your data from the app
  • report bugs or abuse in good faith

You must use the Service only for lawful purposes and only with data you have a right to process.


3. Prohibited Activities

You must not do, attempt, or help others do the following.

3.1 Fraud and unfair Pro access

  • Exploit bugs, race conditions, or webhooks to get Pro, trial, gift, or storage without paying
  • Repeat or stack the one-time trial, forge gift tokens, or create accounts mainly to farm trials or gifts
  • Open chargebacks or payment disputes in bad faith after using Pro
  • Use stolen credentials or payment methods, or impersonate another person

3.2 Security and access controls

  • Bypass authentication, 2FA, passkeys, App Check / reCAPTCHA, rate limits, or Firebase security rules
  • Probe, scan, or attack the Service (including injection and denial-of-service)
  • Access another user’s account, Telegram link, files, groups, or APIs without authorization (including by changing IDs in requests)
  • Share an account to evade Free/Pro limits, or resell access
  • Brute-force vault unlock, OTP, or login beyond normal use

3.3 Other people’s data and groups

  • Read, export, or copy another user’s or group’s data without permission
  • Invite people to a group or share keys in order to leak or harvest their data
  • Use messaging (in-app or Telegram) to phish, spam, or harass

3.4 Telegram and AI

  • Send malware, phishing, or bulk unsolicited messages through our bots or in-app chat
  • Automate high-volume Telegram or AI calls to degrade the Service or evade quotas
  • Feed the bots or AI other people’s personal data you have no right to process
  • Paste secrets you should not store (card PANs, bank passwords, government IDs) — also unsafe because Telegram/AI may see plaintext

3.5 Scraping and automation

  • Scrape, crawl, or harvest the Service or other users’ content
  • Use unofficial bots or scripts against authenticated APIs except as we expressly allow

3.6 Illegal or infringing content

  • Upload or share content that is illegal, or that infringes copyright or other rights
  • Use the Service to commit or plan crime
  • Upload malware

Copyright complaints follow the DMCA Policy.


4. Zero-Knowledge and what we can see

When the vault is on, we cannot read your encrypted expenses, notes, messages, or files. Enforcement for vault content is limited to:

  • account and billing metadata
  • usage patterns, IPs, and security logs
  • file metadata (size, type, upload pattern) for storage
  • reports from other users
  • plaintext you send to AI, Telegram, support, or reviews

We may still suspend an account or disable a feature when abuse is reasonably clear from that evidence. We cannot “look inside” ciphertext to prove or disprove a content complaint.


5. How we detect and respond

We use technical and manual controls that actually exist in the Service, including:

  • rate limits (login, vault, AI, Telegram, OTP, and similar sensitive routes)
  • App Check / reCAPTCHA Enterprise
  • owner checks on APIs
  • one-time trial flags and server-side PayPal price checks
  • session invalidation (single-session)
  • review of logs when we investigate an incident

We do not promise machine-learning fraud models, automatic rollback of your expense records, or a full identity-verification (KYC) product.

If we suspect a violation we may throttle, block a feature (Telegram, AI, storage), freeze a session, revoke fraudulently obtained Pro/trial/gift time, queue the case for review, or close the account.

We may keep investigation records (timestamps, IPs, admin metadata, messages you sent us) as described in the Privacy Policy.


6. Enforcement

If we reasonably believe you broke this AUP, we may, as appropriate:

ActionExample
WarningAsk you to stop
ThrottleTighten rate limits
Feature blockUnlink Telegram, cut AI or uploads
SuspendLock the account while we review
TerminateClose the account
Claw backRemove Pro/trial/gift obtained by abuse
ReportNotify law enforcement for suspected crime

We may act immediately when needed to protect users or the Service. Prepaid fees are generally not refunded when we terminate for cause (see the Terms).


7. Appeals

Email support@simplemoneytracker.com from the address on the account. Include:

  • the account email
  • what happened and when
  • any facts that show the action was wrong

We will review in good faith and try to respond within a reasonable time. Reinstatement, if any, may require you to stop the conduct and secure the account. We do not charge “remediation fees.”


8. Vulnerabilities (responsible disclosure)

If you find a security bug:

  1. Do not exploit it (no extra Pro, no other users’ data, no public dump before we can fix it).
  2. Email admin@simplemoneytracker.com with steps to reproduce. Do not include exploit code aimed at other customers.

Good-faith reports that you did not exploit will not, by themselves, be treated as an AUP violation.


9. Legal requests

We may disclose Administrative Data we hold when the law requires it. We cannot decrypt Vault Data. See the Privacy Policy.


10. Changes

We may update this AUP. The Last Updated date is the version date. Material changes will be posted on this page (and we may also notice you in-app or by email). Continued use after the effective date means you accept the new AUP.

Older versions are listed under Policy History on this page.


11. Contact

Abuse / appeals: support@simplemoneytracker.com
Security disclosure: admin@simplemoneytracker.com
Website: https://simplemoneytracker.com


Summary

TopicRule
AllowedYour own lawful record-keeping, within plan limits
Not allowedFraud, IDOR, scraping, spam, malware, trial farming
VaultWe cannot read ciphertext; we can still act on metadata and reports
DetectionRate limits, App Check, owner checks — not a promised ML/KYC stack
Appealsupport@ from your account email

Policy History

  • 2026-08-15Current Policy
  • 2026-03-31Previous Policy
    reCAPTCHA Enterprise Logo

    protected by reCAPTCHA