Cookie Policy

Service: Simple Money Tracker ("Simple Money Tracker", "we", "us", "our")
Website: https://simplemoneytracker.com

Last Updated: 16/08/2026

This Cookie Policy explains how Simple Money Tracker uses cookies and similar technologies on our website and Service. It should be read together with our Privacy Policy and Terms of Use.

Plain-language summary: We set very few first-party cookies. The only cookies we set ourselves are a consent record, an optional Google Analytics measurement (only if you allow it), and a small sidebar UI cookie in the logged-in app. We do not use cookies to keep you signed in, to run ads, or as a server session. Sign-in, security, theme, and language live in local storage and IndexedDB, not in cookies.


1) What Are Cookies and Similar Technologies?

Cookies are small text files a site stores on your device. The browser sends them back on later visits.

We also use similar technologies that are not HTTP cookies but store data on your device:

  • Local storage and session storage (key/value in the browser)
  • IndexedDB (larger structured storage used by our app and by the Firebase Auth SDK)
  • Tags / scripts such as Google Analytics (gtag.js), which may set cookies after you consent

In this policy, “cookies” means HTTP cookies unless we say “similar technologies.” We describe both so the picture matches how the Service actually works.


2) What We Use Cookies For (and What We Do Not)

What first-party cookies are for

  1. Remember your cookie choice — so we do not ask again on every visit, and so we know whether analytics is allowed.
  2. Optional analytics — if you accept analytics, Google Analytics may set measurement cookies.
  3. In-app sidebar preference — when you expand or collapse the sidebar in the logged-in app.

What we do not use cookies for

We do not use cookies to:

  • keep you logged in or restore your account session
  • store passwords, vault keys, or financial records
  • run advertising, retargeting, or ad measurement (ad_storage is denied)
  • hold a server-side session that our API reads on each request
  • remember language or color theme (those use local storage / your profile)
  • implement a shopping cart, A/B test, or affiliate tracker

How you stay signed in: after you sign in (email, Google, or passkey), the Firebase Authentication SDK stores a refresh token in the browser (IndexedDB, with a local-storage fallback). Our servers authenticate API calls with a short-lived Bearer ID token, not a session cookie. We also keep a device session id in local storage and compare it to your account on our servers so only one active device session is allowed.

Blocking first-party cookies will not log you out by itself. Clearing site data (including IndexedDB) will.


3) Cookies We Set

A) Strictly necessary / essential (first-party)

These support a choice you made or a basic UI preference. They are not used for advertising. You can delete them in the browser; if you delete the consent cookie, we will show the banner again.

sm_consent_status is set by us on this website. It stores your analytics choice (on or off), a timestamp, and a policy version (1.0). It lasts about 12 months (365 days). Cookie Settings cannot turn this cookie off, because it is the record of your choice. Rejecting analytics still writes this cookie, with analytics marked off.

We set sm_consent_status with path=/, SameSite=Lax, and Secure on HTTPS production. It is readable by our site’s JavaScript (it is not HttpOnly) so the banner and Cookie Settings can read it in the browser. We do not copy this record to our servers. If we change the consent version, we treat the old cookie as expired and ask again.

sidebar_state is set by us in the logged-in app only. It records whether the sidebar is expanded or collapsed and lasts about 7 days. There is no separate Cookie Settings toggle for it. It is a UI preference, not analytics.

B) Analytics (optional)

Analytics cookies help us understand how people use the public site and the Service (pages viewed, approximate location from IP at country/city level, device/browser type, and similar events).

We use Google Analytics 4 via gtag.js (measurement id of the form G-…).

Google Analytics may set cookies named _ga, _ga_*, and _gid. These distinguish visitors and sessions. They are set only after you accept analytics (Accept All, or Customize with analytics on).

The Analytics script may load with storage denied by default (Consent Mode). Google is instructed not to write analytics or ads cookies until you grant analytics. Advertising storage stays denied even if you accept analytics. If you reject analytics or later turn it off, we delete first-party cookies whose names start with _ga or _gid.

Analytics data is processed by Google under Google’s policies. Where law requires consent (including many users in the EU/EEA/UK), we treat analytics as consent-based.

C) Marketing / advertising cookies

We do not run third-party ads on the Service and we do not set advertising cookies. If that changes, we will update this policy and ask for consent where required.


4) Similar Technologies (Not Cookies)

These are not HTTP cookies. Cookie Settings does not turn them off, because the app needs them to work. You can clear them by clearing site data in the browser.

IndexedDB (Firebase Auth SDK). The Auth SDK stores your signed-in user and refresh token so you stay signed in across visits until you sign out, we revoke the session, or you clear site data.

IndexedDB (our app). We may cache encrypted vault records and, if you choose, an unlock helper for about 30 days. This is for speed after you unlock the vault. It is not a login cookie.

Local storage. We store things such as a device session id, theme (app-theme, public-theme), language (app-lang), trusted-device tokens for 2FA skip, and light UI caches.

Session storage. Short-lived flags (for example, a “just logged in” marker) that last only for that browser tab.

App Check / reCAPTCHA Enterprise. Tokens in memory or SDK storage help prevent abuse. Google may also set cookies on Google’s own domains when the challenge runs.

Financial records in the vault are encrypted on your device. Cookies are not used to store vault plaintext.


5) Third-Party Cookies and Services

Some cookies or similar identifiers may be set by third parties on their own domains when you use their feature. We do not control those cookies.

Google Analytics. After you allow analytics, Google may set the measurement cookies described in Section 3B.

Google Sign-In. If you choose “Sign in with Google,” Google may set cookies or storage on Google accounts domains for the sign-in popup.

reCAPTCHA Enterprise (Firebase App Check). When the app attests the client, Google may set cookies on Google domains as part of bot and abuse checks.

Google Fonts. Public pages that load fonts make a request to Google’s font hosts. This usually does not set a tracking cookie.

We do not use marketing pixels or social plugins that drop advertising cookies.

Third parties process data under their own terms. See Google Privacy Policy.


6) Cookie Choices and How You Control Them

A) Cookie banner / Cookie Settings

On first visit (or after the consent version changes), a banner lets you:

  • Accept All — essential cookies + analytics
  • Reject All — essential only; analytics stays off; we clean up _ga / _gid cookies if present
  • Customize — turn analytics on or off, then save

Reopen this anytime from Cookie Settings in the website footer.

Cookie Settings only governs website analytics cookies. In-app feature consents (AI, location, Telegram, and similar) are separate. See the Privacy Policy.

B) Browser controls

Most browsers let you view, delete, or block cookies, and clear local storage / IndexedDB. Blocking all cookies may hide the consent banner’s memory of your choice (we will ask again). It will not, by itself, erase your Firebase sign-in data.

C) Google Analytics opt-out

You can also use Google’s Analytics opt-out tools or browser add-ons where available.


7) Consent Records

Your choice is stored only in the sm_consent_status cookie on your device (choice, time, version). We use it to honor the choice and to show we asked. We do not keep a separate server-side cookie-consent log. If you delete that cookie, we will ask again.


8) Do Not Track

Some browsers send a “Do Not Track” (DNT) signal. We do not respond to DNT in a standardized way. We rely on the banner and Cookie Settings instead.


9) Updates to This Cookie Policy

We may update this Cookie Policy when our technology, the law, or our practices change. We will change the Last Updated date and keep prior versions under Policy History on this page.

This version replaces the 27 April 2026 policy. The main change is to describe what we actually store: we no longer describe login, fraud prevention, or load balancing as cookie purposes, because those are not implemented with cookies.


10) Contact

Questions about cookies or similar technologies:


End of Cookie Policy

Policy History

    reCAPTCHA Enterprise Logo

    protected by reCAPTCHA