Privacy policy

What Simple Balance collects, why, who else sees it, and how to get it back or have it deleted — for smpl.money and for the hosted application at app.smpl.money.

This policy covers two things run by the same person: the website at smpl.money, and the hosted application at app.smpl.money. It does not cover a copy of Simple Balance that somebody else runs on their own server — if you are using one of those, the person who runs it decides what happens to your data, and this document is not about them.

Simple Balance is a double-entry ledger. It necessarily holds a detailed record of your money, and that is the whole reason this policy is worth reading rather than skimming.

Who is responsible

The data controller for smpl.money and for the hosted application at app.smpl.money is Gavin Johnson, contactable at info@smpl.money.

For a copy of Simple Balance that somebody else runs, the controller is whoever runs it. That is the whole point of self-hosting, and it means this policy does not describe their deployment and we have no access to it.

The short version

The website collects nothing. There is no analytics, no tracking pixel, and no cookie.

The application holds the ledger you put into it, the account you signed in with, and the operational records needed to run a service — and shares it with nobody except the payment processor and, on the free plan, the advertising network, each described below.

You can export everything as CSV at any time, and deleting your account deletes your data.

What the website collects

Nothing. smpl.money is a set of static files. It sets no cookies, runs no analytics, embeds no third-party scripts, and makes no network requests to anywhere other than itself.

Our hosting provider, Netlify, processes the technical information any web server receives in order to serve a page — your IP address, the page requested, your browser and the time — and retains it briefly for operational and security purposes. We do not analyse it, and we cannot identify you from it.

What the application collects

What you give it. Your name and email address, and everything you enter into the ledger: accounts, balances, transactions, payees, categories, budgets, notes and any file you import. This is the substance of the service and it is stored because the service cannot work otherwise.

How you sign in. A password you set, stored only as a hash that cannot be reversed, or a Google account you chose to connect. Sessions are kept as a signed cookie which is strictly necessary to keep you signed in.

Operational records. Server logs, which include IP addresses and request paths, kept briefly for security and debugging. An audit history of changes to your own ledger, which is part of the product and visible to you.

If you subscribe. Your subscription's status and the identifiers Stripe gives us. We never see or store your card details — they go directly to Stripe.

Why we are allowed to hold it

Where the UK GDPR and the EU GDPR apply, the lawful bases are: performance of a contract, for your account and the ledger itself, without which there is no service to provide; legitimate interests, for security logging and fraud prevention, balanced against your rights and kept to what is necessary; legal obligation, for the financial records a payment processor and we must keep; and consent, for personalised advertising and for optional emails, which you may withdraw at any time.

Advertising, on the free plan

The hosted application shows advertising to accounts on the free plan, supplied by Google AdSense. Paid accounts are shown no advertising, and — because the server decides and the browser is never told the rule — a paid account does not load Google's script at all.

Google and its partners use cookies and similar technologies to serve ads. Ads are requested as non-personalised by default, which means they are based on the page and your rough location rather than on a profile of you.

Non-personalised is not the same as cookie-free. Even these ads set cookies, for frequency capping and fraud prevention, which is why consent is asked for in the EEA, the UK and Switzerland regardless of whether the ads are personalised. That consent is collected through Google's own certified consent platform before any ad cookie is set, and you can change or withdraw it at any time from the same notice. Declining means no ads are served to you.

Ads are only ever personalised if you have consented to that specifically.

Google's own description of how it uses data from sites that use its services is at policies.google.com/technologies/partner-sites. You can control ad personalisation across Google's products at myadcenter.google.com, and opt out of third-party vendor cookies at aboutads.info and youronlinechoices.eu.

Advertising never appears on the billing page or the sign-in screen.

Payments

Payments are processed by Stripe. When you subscribe, your card details are collected by Stripe's own form and sent directly to Stripe; they do not pass through our servers and we never store them.

We store the identifiers Stripe returns, your subscription's status, and which plan you are on, because those are what decide what your account may do. Stripe's privacy policy is at stripe.com/privacy.

Email

Email you asked for. Confirming your address, resetting a password, and reminders about recurring transactions if you turn them on. These stop when you stop asking for them.

Email about the service itself — planned maintenance, a change that affects your data, a feature being retired, a security matter. These are part of running the service rather than marketing, so they are sent to every account and there is no unsubscribe from them. We keep them rare and we keep them factual.

Occasional email about the product, such as a significant new capability. Every one carries an unsubscribe link that works immediately and without signing in, and unsubscribing from these does not affect the two kinds above. If you would rather not receive any, say so when you create the account or unsubscribe from the first.

There is no newsletter, nothing is sold to a mailing-list broker, and your address is never shared for anybody else's marketing.

A deployment configured with no mail server sends none of these, and the features that need them are simply absent rather than broken.

Who else sees your data

Nobody, other than the processors needed to run the service, and we do not sell it, rent it, or share it for anyone else's marketing.

Those processors are: our hosting and database provider, which stores the data; Stripe, for payments; Google, for advertising on the free plan and for Google sign-in if you use it; and an email provider, for the messages above.

We will disclose data if we are legally required to, and we will tell you unless we are prohibited from doing so.

Where it is held, and for how long

Data for the hosted application is stored on servers in the United States. Where you are in the UK or the EEA, transfers rely on the UK Addendum and the European Commission's Standard Contractual Clauses.

Your ledger is kept until you delete it or delete your account. Server logs are kept for a short operational period. Records of payments are kept as long as tax and accounting law requires, typically six years, and that is the one category that survives deleting your account.

Deleting your account

You can delete your account from the settings page. It removes your ledger, your account and every associated record in one operation, and it cancels any subscription at the same time. It cannot be undone, which is why exporting first is worth doing.

Deletion is refused rather than partially completed if the payment processor cannot be reached to cancel a subscription, so that nobody is left being charged for an account that no longer exists.

Your rights

Where the UK or EU GDPR applies you have the right to access your data, to correct it, to have it erased, to restrict or object to how it is used, and to receive it in a portable form. The California Consumer Privacy Act gives California residents comparable rights, including the right not to be discriminated against for exercising them. We do not sell or share personal information as those laws define it.

Most of these you can exercise yourself and immediately: the product has CSV export for portability, editing for correction, and account deletion for erasure. For anything else, write to the address below and we will answer within one month.

If you are not satisfied, you may complain to your data protection authority — in the UK, the Information Commissioner's Office at ico.org.uk.

Children

The service is not directed at children under 16 and we do not knowingly collect their data. If you believe a child has created an account, write to us and we will delete it.

Cookies, and why this site has no banner

smpl.money sets no cookies at all. No analytics, no tracking pixel, no third-party script. There is nothing to ask you about, so there is no banner — a consent notice on a site that stores nothing would be theatre.

The application sets two of its own. A session cookie, which is strictly necessary to keep you signed in, and a preference cookie remembering whether you chose the light or dark theme. Neither is used for anything else, neither is shared, and neither requires consent: one is essential to a service you asked for, the other stores a choice you made.

On the free plan, Google sets cookies for advertising, and those are the ones that do require your consent. If you are in the EEA, the UK or Switzerland, you will be asked before any of them are set, through a consent notice provided by Google's own certified consent platform. You can change or withdraw that choice at any time from the same notice.

Declining means you see no advertising. It does not limit the product in any other way, and nothing about your account changes.

Changes

If this policy changes materially we will say so on this page and, where the change affects how your data is used, by email before it takes effect.

Contact

Write to info@smpl.money about anything on this page, or anything else. There is a person at the other end.