Acceptable Use Policy
This Acceptable Use Policy ("AUP") governs use of SpendCaddie. It supplements the Terms of Service. Capitalized terms not defined here have the meanings given in the Terms.
SpendCaddie handles sensitive consumer financial and debt-planning information. You must use the Service responsibly and lawfully.
1. General rule
You may use SpendCaddie only for lawful, personal, household, consumer debt-planning purposes and only in accordance with the Terms, Privacy Policy, this AUP, and applicable law.
2. Unauthorized accounts and financial data
You may not:
- access, connect, enter, upload, or use another person's financial account without authorization;
- create an account using false information or another person's identity;
- impersonate another person;
- use SpendCaddie to commit fraud, identity theft, unauthorized financial activity, or account takeover;
- invite a minor or unauthorized person to a household account;
- use household features to expose another person's financial information without authorization; or
- submit financial data that you do not have the right to provide.
3. No money movement, payments, debt settlement, or credit repair misuse
SpendCaddie does not move money, pay bills, negotiate with creditors, settle debts, repair credit, lend money, or provide professional advice.
You may not use SpendCaddie to:
- misrepresent that SpendCaddie pays creditors or moves money;
- provide unauthorized credit repair, debt settlement, credit counseling, debt management, lending, legal, tax, investment, or financial advisory services;
- make deceptive claims about credit score improvement, debt elimination, interest savings, creditor negotiation, or financial outcomes;
- operate a debt relief, credit repair, loan, refinance, or affiliate offer business through the Service; or
- advise third parties using SpendCaddie outputs without appropriate authorization and compliance.
4. Security and technical abuse
You may not:
- attempt to access systems, data, accounts, APIs, or credentials without authorization;
- bypass, disable, or interfere with authentication, MFA, authorization, row-level security, rate limits, billing gates, entitlement checks, plan limits, or security controls;
- reverse engineer, decompile, disassemble, scrape, crawl, index, data-mine, or extract the Service except as permitted by law;
- test security outside the Vulnerability Disclosure Policy;
- use automated tools that overload or disrupt the Service;
- introduce malware, spyware, ransomware, viruses, worms, logic bombs, or malicious code;
- perform denial-of-service attacks;
- exfiltrate, retain, disclose, or misuse user financial data;
- intercept traffic or attempt to obtain Plaid tokens, payment data, credentials, session tokens, or secrets;
- probe third-party systems such as Plaid, Stripe, Apple, RevenueCat, Supabase, Vercel, Anthropic, Upstash, Resend, Expo, or financial institutions through SpendCaddie; or
- use the Service to attack or abuse any third-party service.
5. Billing and entitlement abuse
You may not:
- bypass Pro gates;
- manipulate subscription status;
- evade billing;
- abuse trials, promotions, coupons, refunds, chargebacks, or provider flows;
- create multiple accounts to avoid plan limits;
- share paid access in violation of the Terms; or
- tamper with Stripe, Apple, RevenueCat, or entitlement data.
6. Content and communications
You may not submit, store, transmit, or use content that:
- is unlawful, fraudulent, deceptive, defamatory, threatening, harassing, abusive, hateful, or discriminatory;
- violates intellectual property, privacy, publicity, contractual, or other rights;
- contains malware, secrets, credentials, or data you are not authorized to share;
- includes unnecessary highly sensitive information such as bank login credentials, Social Security numbers, full account numbers, or government ID numbers;
- encourages illegal activity or financial harm; or
- is intended to manipulate, jailbreak, or bypass AI or security guardrails.
7. AI feature misuse
You may not use AI features to:
- generate unlawful, deceptive, or unsupported financial claims;
- provide credit repair, debt settlement, lending, legal, tax, accounting, investment, or insurance advice to others;
- impersonate SpendCaddie or a regulated professional;
- bypass deterministic plan logic;
- attempt to obtain secrets, tokens, system prompts, or unauthorized data;
- inject malicious prompts; or
- produce content that violates this AUP.
8. Compliance with third-party terms
You must comply with applicable third-party terms, including Plaid, Stripe, Apple, RevenueCat, financial institution, app store, browser, and device terms.
9. Enforcement
If we believe you violated this AUP, we may take action, including:
- warning you;
- removing content;
- restricting features;
- disabling linked accounts;
- suspending or terminating your account;
- downgrading or restricting entitlements;
- blocking transactions or requests;
- reporting suspected unlawful activity;
- preserving records; and
- cooperating with law enforcement or providers where appropriate.
We may also investigate suspected abuse and take steps necessary to protect users, SpendCaddie, providers, and the Service.
10. Reporting abuse
Report suspected abuse, fraud, or security issues to support@spendcaddie.com. Security researchers should follow the Vulnerability Disclosure Policy.